CVE-2015-3097
published 2015-06-10CVE-2015-3097: Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK &…
PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
12.00%
95.7th percentile
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 17.0.0.172 | — |
| adobe | air_sdk | <= 17.0.0.172 | — |
| adobe | air_sdk_compiler | <= 17.0.0.172 | — |
| adobe | flash_player | <= 13.0.0.289 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5g7h-j329-988v: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2015-3097 [MEDIUM] CWE-200 GHSA-5g7h-j329-988v: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address.
OSV
CVE-2015-3097: Adobe Flash Player before 13
osv·2015-06-10·CVSS 5.0
CVE-2015-3097 [MEDIUM] CVE-2015-3097: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/75090http://www.securitytracker.com/id/1032519http://www.securitytracker.com/id/1032810https://helpx.adobe.com/security/products/flash-player/apsb15-11.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb15-16.htmlhttps://security.gentoo.org/glsa/201506-01http://www.securityfocus.com/bid/75090http://www.securitytracker.com/id/1032519http://www.securitytracker.com/id/1032810https://helpx.adobe.com/security/products/flash-player/apsb15-11.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb15-16.htmlhttps://security.gentoo.org/glsa/201506-01
2015-06-10
Published