Vulnerability Description
Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafted text property, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430, CVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434, CVE-2015-8435, CVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442, CVE-2015-8447, CVE-2015-8448, CVE-2015-8449, CVE-2015-8450, CVE-2015-8452, CVE-2015-8454, CVE-2015-8653, CVE-2015-8655, CVE-2015-8821, and CVE-2015-8822.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 8.0 | All versions |
| Microsoft | Windows 8.1 | All versions |
| Adobe | Flash Player | <= 19.0.0.245 |
| Adobe | Air | <= 19.0.0.241 |
| Apple | Mac Os X | - |
| Android | - | |
| Microsoft | Windows | - |
| Chrome Os | - | |
| Linux | Linux Kernel | - |
| Microsoft | Windows 10 | - |
| Adobe | Air Sdk | <= 19.0.0.241 |
| Apple | Iphone Os | - |
| Adobe | Air Sdk \& Compiler | <= 19.0.0.241 |
| Adobe | Flash Player Desktop Runtime | <= 19.0.0.245 |
Related Weaknesses (CWE)
References
- http://www.zerodayinitiative.com/advisories/ZDI-15-665Third Party AdvisoryVDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb15-32.htmlPatchVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-15-665Third Party AdvisoryVDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb15-32.htmlPatchVendor Advisory
FAQ
What is CVE-2015-8823?
CVE-2015-8823 is a vulnerability with a CVSS score of 8.8 (HIGH). Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Ad...
How severe is CVE-2015-8823?
CVE-2015-8823 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8823?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 8.0, Microsoft Windows 8.1, Adobe Flash Player, Adobe Air, Apple Mac Os X.