CVE-2015-6676Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe AIR

Severity
10.0CRITICALNVD
EPSS
2.7%
top 14.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22
Latest updateMay 17

Description

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6678.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages4 packages

NVDadobe/flash_player11.2.202.508+25
NVDadobe/air_sdk_compiler18.0.0.180
NVDadobe/air18.0.0.199+1
NVDadobe/air_sdk18.0.0.199

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f8wh-23gc-q2m2: Buffer overflow in Adobe Flash Player before 182022-05-17
CVEList
CVE-2015-6676: Buffer overflow in Adobe Flash Player before 182015-09-22
OSV
CVE-2015-6676: Buffer overflow in Adobe Flash Player before 182015-09-22

📋Vendor Advisories

2
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-232015-09-21
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-232015-09-21

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-232015-09-21
CVE-2015-6676 — Adobe AIR vulnerability | cvebase