HIGH · 10.0

CVE-2015-6676

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, a...

Vulnerability Description

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6678.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AdobeAir<= 18.0.0.199
AdobeAir Sdk<= 18.0.0.199
AdobeAir Sdk \& Compiler<= 18.0.0.180
AppleMac Os X-
MicrosoftWindows-
AdobeFlash Player<= 11.2.202.508
LinuxLinux Kernel-
GoogleAndroidAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-6676?

CVE-2015-6676 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, a...

How severe is CVE-2015-6676?

CVE-2015-6676 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-6676?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Air, Adobe Air Sdk, Adobe Air Sdk \& Compiler, Apple Mac Os X, Microsoft Windows.