CVE-2015-7659

Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion" in the NetConnection object implementation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
adobeflash_player
𝑥
≤ 11.2.202.540
adobeair
𝑥
≤ 19.0.0.213
adobeflash_player
𝑥
≤ 18.0.0.255
adobeflash_player
19.0.0.185
adobeflash_player
19.0.0.207
adobeflash_player
19.0.0.226
adobeair
𝑥
≤ 19.0.0.190
adobeair_sdk
𝑥
≤ 19.0.0.213
adobeair_sdk_\&_compiler
𝑥
≤ 19.0.0.213
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
wily
Fixed 1:20151110.1-0wily1
released
vivid
Fixed 1:20151110.1-0vivid1
released
trusty
Fixed 1:20151110.1-0trusty1
released
precise
Fixed 1:20151110.1-0precise1
released
flashplugin-nonfree
wily
Fixed 11.2.202.548ubuntu0.15.10.1
released
vivid
Fixed 11.2.202.548ubuntu0.15.04.1
released
trusty
Fixed 11.2.202.548ubuntu0.14.04.1
released
precise
Fixed 11.2.202.548ubuntu0.12.04.1
released