CVE-2015-3040: Infoleak
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-0357.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3040?
CVE-2015-3040 is considered high severity as it allows attackers to bypass ASLR protections.
How do I fix CVE-2015-3040?
To fix CVE-2015-3040, update Adobe Flash Player to version 17.0.0.169 or later.
Which versions of Adobe Flash Player are affected by CVE-2015-3040?
Adobe Flash Player versions prior to 13.0.0.281 and 14.x through 17.x before 17.0.0.169 are affected.
Are there any specific operating systems vulnerable to CVE-2015-3040?
Yes, CVE-2015-3040 affects Adobe Flash Player on Windows, OS X, and Linux platforms.
What is the impact of CVE-2015-3040 on systems?
The impact of CVE-2015-3040 includes potential unauthorized access to sensitive data and execution of arbitrary code.