First published: Wed May 13 2015(Updated: )
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-3084 and CVE-2015-3086.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.475 | |
Linux Kernel | ||
Adobe Flash Player for Internet Explorer 11 | <=13.0.0.264 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.125 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.145 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.176 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.179 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.152 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.167 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.189 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.223 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.239 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.246 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.235 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.257 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.287 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.296 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.134 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.169 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe AIR | <=17.0.0.144 | |
Adobe AIR SDK and Compiler | <=17.0.0.144 | |
Adobe AIR SDK & Compiler | <=17.0.0.144 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3077 has been assigned a critical severity rating due to its potential to allow attackers to execute arbitrary code remotely.
To fix CVE-2015-3077, update Adobe Flash Player to version 17.0.0.188 or later, or upgrade to the latest version of Adobe AIR if you are using that software.
CVE-2015-3077 affects Adobe Flash Player versions prior to 17.0.0.188 and Adobe AIR versions before 17.0.0.172, as well as various versions of the AIR SDK.
You can check your Adobe Flash Player version and compare it against the affected versions listed for CVE-2015-3077 to determine vulnerability.
CVE-2015-3077 is considered a common vulnerability as Adobe Flash Player has been a frequent target for exploits due to its widespread use.