SUSE-SU-2015:1043Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00005.html CVE-2015-3104
Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution
Record summary
CVE-2015-3104 has a selected CVSS score of 10.0.
Description
Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 30, 2015 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
References
9openSUSE-SU-2015:1047Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00009.html openSUSE-SU-2015:1061Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00011.html RHSA-2015:1086Vendor advisory
http://rhn.redhat.com/errata/RHSA-2015-1086.html 75081vdb entry
http://www.securityfocus.com/bid/75081 1032519vdb entry
http://www.securitytracker.com/id/1032519 helpx.adobe.comConfirmation
https://helpx.adobe.com/security/products/flash-player/apsb15-11.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-3104 GLSA-201506-01Vendor advisory
https://security.gentoo.org/glsa/201506-01