CVE-2015-8636
published 2015-12-28CVE-2015-8636: Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233…
PriorityP264high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
21.35%
97.3th percentile
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 20.0.0.204 | — |
| adobe | air_sdk | <= 20.0.0.204 | — |
| adobe | air_sdk_compiler | <= 20.0.0.204 | — |
| adobe | flash_player | <= 18.0.0.268 | — |
| adobe | flash_player | <= 11.2.202.554 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2015-8636 is an out-of-bounds memset triggered during BlurFilter processing in Adobe Flash Player; monitor for SWF files that cause abnormal BlurFilter handling or Flash process crashes/aborts. ↗
- →Target affected versions: Adobe Flash Player before 18.0.0.324, 19.x and 20.x before 20.0.0.267 (Windows/OS X), before 11.2.202.559 (Linux); Adobe AIR before 20.0.0.233 — flag installations running these versions. ↗
- ·CVE-2015-8636 is grouped with CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645 as distinct memory corruption vulnerabilities fixed in the same Adobe patch (APSB16-01); ensure detections differentiate between these four CVEs. ↗
- ·The exploit PoC is delivered as a crafted SWF file inside a ZIP archive; detection should account for SWF payloads delivered via archive containers. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 10.0
CVE-2015-8645 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8636.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 10.0
CVE-2015-8636 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 10.0
CVE-2015-8460 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8636, and CVE-2015-8645.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 10.0
CVE-2015-8459 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8460, CVE-2015-8636, and CVE-2015-8645.
Red Hat
Mozilla: XrayWrapper bypass through DOM objects (MFSA 2015-09)
vendor_redhat·2014-01-15·CVSS 7.5
CVE-2014-8636 [HIGH] CWE-250 Mozilla: XrayWrapper bypass through DOM objects (MFSA 2015-09)
Mozilla: XrayWrapper bypass through DOM objects (MFSA 2015-09)
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-386r-pqqg-j97c: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-8636 [CRITICAL] CWE-119 GHSA-386r-pqqg-j97c: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645.
GHSA
GHSA-4qvm-xjjr-jfjj: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-8645 [CRITICAL] CWE-119 GHSA-4qvm-xjjr-jfjj: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8636.
GHSA
GHSA-q986-4c56-gm92: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-8460 [CRITICAL] CWE-119 GHSA-q986-4c56-gm92: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8636, and CVE-2015-8645.
GHSA
GHSA-mfxr-fj8r-f93p: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8459 [HIGH] CWE-119 GHSA-mfxr-fj8r-f93p: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8460, CVE-2015-8636, and CVE-2015-8645.
OSV
CVE-2015-8636: Adobe Flash Player before 18
osv·2015-12-28·CVSS 10.0
CVE-2015-8636 [CRITICAL] CVE-2015-8636: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645.
OSV
CVE-2015-8460: Adobe Flash Player before 18
osv·2015-12-28·CVSS 10.0
CVE-2015-8460 [CRITICAL] CVE-2015-8460: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8636, and CVE-2015-8645.
OSV
CVE-2015-8459: Adobe Flash Player before 18
osv·2015-12-28·CVSS 10.0
CVE-2015-8459 [CRITICAL] CVE-2015-8459: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8460, CVE-2015-8636, and CVE-2015-8645.
OSV
CVE-2015-8645: Adobe Flash Player before 18
osv·2015-12-28·CVSS 10.0
CVE-2015-8645 [CRITICAL] CVE-2015-8645: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8636.
Suricata
ET WEB_CLIENT Firefox Proxy Prototype RCE Attempt (CVE-2014-8636)
suricata·2015-03-26·CVSS 7.5
CVE-2014-8636 [HIGH] ET WEB_CLIENT Firefox Proxy Prototype RCE Attempt (CVE-2014-8636)
ET WEB_CLIENT Firefox Proxy Prototype RCE Attempt (CVE-2014-8636)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Firefox Proxy Prototype RCE Attempt (CVE-2014-8636)"; flow:established,to_client; file.data; content:"chrome|3a 2f 2f|"; nocase; content:"open"; nocase; pcre:"/^\s*?\(\s*?[\x22\x27]chrome\x3a\/\//Ri"; content:"messageManager.loadFrameScript"; nocase; content:"Proxy.create"; nocase; reference:url,community.rapid7.com/community/metasploit/blog/2015/03/23/r7-2015-04-disclosure-mozilla-firefox-proxy-prototype-rce-cve-2014-8636; reference:cve,2014-8636; classtype:attempted-user; sid:2020756; rev:3; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2015_03_26, cve CVE_2014_8636, deployment
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-29-2015
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-29-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-01
bugzilla·2015-12-29·CVSS 10.0
CVE-2015-8644 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Adobe Security Bulletin APSB16-01 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-01:
These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2015-8644).
These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2015-8651).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650).
These updates resolv
Bugzilla
CVE-2014-8636 Mozilla: XrayWrapper bypass through DOM objects (MFSA 2015-09)
bugzilla·2015-01-12·CVSS 7.5
CVE-2014-8636 [HIGH] CVE-2014-8636 Mozilla: XrayWrapper bypass through DOM objects (MFSA 2015-09)
CVE-2014-8636 Mozilla: XrayWrapper bypass through DOM objects (MFSA 2015-09)
Mozilla developer Bobby Holley reported that Document Object Model (DOM) objects with some specific properties can bypass XrayWrappers. This can allow web content to access privileged code by compromising their XrayWrappers.
External Reference:
http://www.mozilla.org/security/announce/2015/mfsa2015-09.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Bobby Holley as the original reporter.
Statement:
This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2697.htmlhttp://www.securityfocus.com/bid/79700http://www.securitytracker.com/id/1034544https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlhttps://security.gentoo.org/glsa/201601-03https://www.exploit-db.com/exploits/39219/http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2697.htmlhttp://www.securityfocus.com/bid/79700http://www.securitytracker.com/id/1034544https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlhttps://security.gentoo.org/glsa/201601-03https://www.exploit-db.com/exploits/39219/
2015-12-28
Published