CVE-2015-8459

Description

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8460, CVE-2015-8636, and CVE-2015-8645.

Risk Information

Base Score
10.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.401

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe flash player 20.0.0.235 to latest versionWindows
Upgrade air 20.0.0.204 to latest versionWindows
Multiple vulnerabilities affected in Adobe Flash Player Plugin 20.0.0.235Windows
Multiple vulnerabilities affected in Adobe Flash Player PPAPI 20.0.0.235Windows
Multiple Vulnerabilities are affected in Adobe AIR For Mac 20.0.0.204Mac
SUSE-SU-2015:2402-1(SUSE Linux Enterprise Desktop 11-SP3 ) flash-player-11.2.202.559-0.32.1.x86_64.rpmLinux
SUSE-SU-2015:2402-1(SUSE Linux Enterprise Desktop 11-SP3 ) flash-player-gnome-11.2.202.559-0.32.1.x86_64.rpmLinux
SUSE-SU-2015:2402-1(SUSE Linux Enterprise Desktop 11-SP3 ) flash-player-kde4-11.2.202.559-0.32.1.x86_64.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234