cbcvebase.
CVE-2015-5576
published 2015-09-22

CVE-2015-5576: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR…

medium5CVSS 3.1
AVNACLAuNCPINAN
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
adobeair<= 18.0.0.199
adobeair<= 18.0.0.143
adobeair_sdk<= 18.0.0.199
adobeair_sdk_compiler<= 18.0.0.180
adobeflash_player<= 13.0.0.289
adobeflash_player<= 11.2.202.508
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM