« Volver al listado

CVE-2015-3097

Estado: ModificadaMedia (5)—

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-3097",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-06-10T01:59:40.703",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/75090",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1032519",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1032810",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-11.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-16.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/201506-01",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/75090",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1032519",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1032810",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-11.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-16.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201506-01",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address."
    },
    {
      "lang": "es",
      "value": "Adobe Flash Player anterior a 13.0.0.292 y 14.x hasta 18.x anterior a 18.0.0.160, Adobe AIR anterior a 18.0.0.144, Adobe AIR SDK anterior a 18.0.0.144, y Adobe AIR SDK & Compiler anterior a 18.0.0.144 en los sistemas de Windows 7 de 64 bits no seleccionan correctamente una dirección de la memoria aleatoria para la memoria dinámica de Flash, lo que facilita a atacantes realizar ataques no especificadas mediante la predicción de esta dirección."
    }
  ],
  "lastModified": "2026-06-17T00:25:17.280",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4D3CA52-FE42-4B46-92FF-E8B027F586BF",
              "versionEndIncluding": "17.0.0.172"
            },
            {
              "criteria": "cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F5DDA65-B2BF-4299-9A1E-C61BB08A70FB",
              "versionEndIncluding": "17.0.0.172"
            },
            {
              "criteria": "cpe:2.3:a:adobe:air_sdk_\\&_compiler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E9D89B2-3A2E-406F-8DD4-19078091E7F5",
              "versionEndIncluding": "17.0.0.172"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2E515D4-87A7-4CB5-8C91-0A95BE8F283B",
              "versionEndIncluding": "13.0.0.289"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5D7202D-56DF-400B-9F09-E7D9938222D3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D4F0D21-A64B-46C1-9591-96529661DF0B"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86961019-3B81-458E-949F-A2F006EA55FE"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25895BE9-71FD-4DE7-90FC-0199470A8738"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D55A950-7D48-413C-AD43-6AC64FBE790C"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1A22B74-453D-4A8A-B79A-2B3143A0D995"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FE4B077-67D1-4B25-976E-715FB6B2A1D1"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFC91B68-6B35-47BD-BC02-3F836E772CF3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3BE6004-C30A-46E2-9F25-785E12BBF640"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFE8E51F-7A32-41A4-B03A-73E52EB64C04"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E13E927-A77C-4681-AFDE-A5A14093234D"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27629FF0-5EB9-476F-B5B3-115F663AB65E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0AB583F-3EBD-47B6-975E-7754CC32CCA7"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B58DE1A9-0510-4B65-AB18-75F9263A7818"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BC4FAD0-4A54-4EDF-BE39-28138B34E719"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE1FBC20-3DE6-4426-9E97-42AFCEF8CEE4"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40EF2221-DE87-4D8F-B92D-8FD21EEBEABA"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "DEB02D84-ADC8-4297-B388-D5BDA4EB4B82"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}