CVE-2015-8635
published 2015-12-28CVE-2015-8635: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux…
PriorityP260high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
25.47%
97.7th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 20.0.0.204 | — |
| adobe | air_sdk | <= 20.0.0.204 | — |
| adobe | air_sdk_compiler | <= 20.0.0.204 | — |
| adobe | flash_player | <= 18.0.0.268 | — |
| adobe | flash_player | <= 11.2.202.554 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Use-after-free triggered during display rendering with multiple scripts in Adobe Flash Player; crash may be delayed (minutes) in release builds but immediate in debug builds — monitor for Flash Player crashes or heap corruption signals during rendering activity. ↗
- →Target Adobe Flash Player versions below 18.0.0.324, 19.x/20.x below 20.0.0.267 (Windows/OS X), and below 11.2.202.559 (Linux); flag processes running these versions. ↗
- ·The NVD source (CVE-2015-8650) covers a family of related use-after-free CVEs; CVE-2015-8635 is one of 13 sibling vulnerabilities sharing the same affected version ranges and attack vector description. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whmw-g3g3-wh9q: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8642 [HIGH] GHSA-whmw-g3g3-wh9q: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-99pr-h8j7-g6rh: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8649 [HIGH] GHSA-99pr-h8j7-g6rh: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, and CVE-2015-8650.
GHSA
GHSA-fh2x-r8vx-29x5: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8643 [HIGH] GHSA-fh2x-r8vx-29x5: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-8rrr-5jm3-f8x3: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8647 [HIGH] GHSA-8rrr-5jm3-f8x3: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-vq2r-39mj-3fw5: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8634 [HIGH] GHSA-vq2r-39mj-3fw5: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-jp5c-fmrf-xg6p: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8640 [HIGH] GHSA-jp5c-fmrf-xg6p: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-wgw3-qjcr-m37w: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8646 [HIGH] GHSA-wgw3-qjcr-m37w: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-j7x2-6vg8-52xp: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8641 [HIGH] GHSA-j7x2-6vg8-52xp: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-2856-5p3x-qmfp: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8635 [HIGH] GHSA-2856-5p3x-qmfp: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-mpv5-ww22-248q: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8638 [HIGH] GHSA-mpv5-ww22-248q: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-54rg-92mr-667r: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8650 [HIGH] GHSA-54rg-92mr-667r: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, and CVE-2015-8649.
GHSA
GHSA-2p9g-cjmm-h5pq: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8648 [HIGH] GHSA-2p9g-cjmm-h5pq: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8649, and CVE-2015-8650.
GHSA
GHSA-8j7x-7jhf-rxq4: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8639 [HIGH] GHSA-8j7x-7jhf-rxq4: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8639: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8639 [HIGH] CVE-2015-8639: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8635: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8635 [HIGH] CVE-2015-8635: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8646: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8646 [HIGH] CVE-2015-8646: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8648: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8648 [HIGH] CVE-2015-8648: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8650: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8650 [HIGH] CVE-2015-8650: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, and CVE-2015-8649.
OSV
CVE-2015-8643: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8643 [HIGH] CVE-2015-8643: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8640: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8640 [HIGH] CVE-2015-8640: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8642: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8642 [HIGH] CVE-2015-8642: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8638: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8638 [HIGH] CVE-2015-8638: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8649: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8649 [HIGH] CVE-2015-8649: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, and CVE-2015-8650.
OSV
CVE-2015-8634: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8634 [HIGH] CVE-2015-8634: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8647: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8647 [HIGH] CVE-2015-8647: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
OSV
CVE-2015-8641: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8641 [HIGH] CVE-2015-8641: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8638 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8650 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, and CVE-2015-8649.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8648 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8634 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8646 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8639 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8640 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8642 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8641 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8647 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8635 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8649 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, and CVE-2015-8650.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8643 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:35.0) (MFSA 2015-01)
vendor_redhat·2015-01-15·CVSS 7.5
CVE-2014-8635 [HIGH] CWE-122 Mozilla: Miscellaneous memory safety hazards (rv:35.0) (MFSA 2015-01)
Mozilla: Miscellaneous memory safety hazards (rv:35.0) (MFSA 2015-01)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-29-2015
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-29-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-01
bugzilla·2015-12-29·CVSS 10.0
CVE-2015-8644 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Adobe Security Bulletin APSB16-01 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-01:
These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2015-8644).
These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2015-8651).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650).
These updates resolv
Bugzilla
CVE-2014-8635 Mozilla: Miscellaneous memory safety hazards (rv:35.0) (MFSA 2015-01)
bugzilla·2015-01-12·CVSS 7.5
CVE-2014-8635 [HIGH] CVE-2014-8635 Mozilla: Miscellaneous memory safety hazards (rv:35.0) (MFSA 2015-01)
CVE-2014-8635 Mozilla: Miscellaneous memory safety hazards (rv:35.0) (MFSA 2015-01)
Mozilla developers and community identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
In general these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled, but are potentially a risk in browser or browser-like contexts.
Christoph Diehl, Christian Holler, Gary Kwong, Jesse Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier reported memory safety problems and crashes that affect Firefox 34.
External Ref
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2697.htmlhttp://www.securityfocus.com/bid/79701http://www.securitytracker.com/id/1034544https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlhttps://security.gentoo.org/glsa/201601-03https://www.exploit-db.com/exploits/39220/http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2697.htmlhttp://www.securityfocus.com/bid/79701http://www.securitytracker.com/id/1034544https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlhttps://security.gentoo.org/glsa/201601-03https://www.exploit-db.com/exploits/39220/
2015-12-28
Published