« Volver al listado

CVE-2015-3081

Estado: ModificadaMedia (4.3)—💥 Exploit

Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to bypass the Internet Explorer Protected Mode protection mechanism via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-3081",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-05-13T11:00:13.563",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/74613",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1032285",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-09.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/201505-02",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://www.exploit-db.com/exploits/37842/",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/74613",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1032285",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-09.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201505-02",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/37842/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to bypass the Internet Explorer Protected Mode protection mechanism via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Condición de carrera en Adobe Flash Player anterior a 13.0.0.289 y 14.x hasta 17.x anterior a 17.0.0.188 en Windows y OS X y anterior a 11.2.202.460 en Linux, Adobe AIR anterior a 17.0.0.172, Adobe AIR SDK anterior a 17.0.0.172, y Adobe AIR SDK & Compiler anterior a 17.0.0.172 permite a atacantes evadir el mecanismo de protección del modo protegido de Internet Explorer a través de vectores no esp3ecificados."
    }
  ],
  "lastModified": "2026-06-17T00:25:15.350",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60818E16-3EBF-4468-9349-D5BE1882BF88",
              "versionEndIncluding": "11.2.202.475"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EA9C9E9-32C6-40F1-920D-970ABA6A94FB",
              "versionEndIncluding": "17.0.0.144"
            },
            {
              "criteria": "cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3500098A-637C-4D4B-8AF1-5E6ED8793457",
              "versionEndIncluding": "17.0.0.144"
            },
            {
              "criteria": "cpe:2.3:a:adobe:air_sdk_\\&_compiler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "949A1AEB-CB1D-4E89-BA7A-ED6EC313BBAB",
              "versionEndIncluding": "17.0.0.144"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35A39AB2-E3C6-4C70-8CC9-0050184DB2B5",
              "versionEndIncluding": "13.0.0.264"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5D7202D-56DF-400B-9F09-E7D9938222D3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D4F0D21-A64B-46C1-9591-96529661DF0B"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86961019-3B81-458E-949F-A2F006EA55FE"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25895BE9-71FD-4DE7-90FC-0199470A8738"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D55A950-7D48-413C-AD43-6AC64FBE790C"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1A22B74-453D-4A8A-B79A-2B3143A0D995"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FE4B077-67D1-4B25-976E-715FB6B2A1D1"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFC91B68-6B35-47BD-BC02-3F836E772CF3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3BE6004-C30A-46E2-9F25-785E12BBF640"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFE8E51F-7A32-41A4-B03A-73E52EB64C04"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E13E927-A77C-4681-AFDE-A5A14093234D"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27629FF0-5EB9-476F-B5B3-115F663AB65E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0AB583F-3EBD-47B6-975E-7754CC32CCA7"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B58DE1A9-0510-4B65-AB18-75F9263A7818"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BC4FAD0-4A54-4EDF-BE39-28138B34E719"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE1FBC20-3DE6-4426-9E97-42AFCEF8CEE4"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4781BF1E-8A4E-4AFF-9540-23D523EE30DD"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}