CVE-2015-5576: Infoleak
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5576?
CVE-2015-5576 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2015-5576?
To fix CVE-2015-5576, users should update Adobe Flash Player and Adobe AIR to the latest versions provided by Adobe.
What software versions are affected by CVE-2015-5576?
CVE-2015-5576 affects Adobe Flash Player versions before 18.0.0.241 and 19.x before 19.0.0.185, along with multiple versions of Adobe AIR.
What are the potential impacts of CVE-2015-5576?
The potential impacts of CVE-2015-5576 include unauthorized access and control over the compromised system by an attacker.
Is it safe to use older versions of Adobe Flash Player and AIR?
Using older versions of Adobe Flash Player and AIR is unsafe due to the vulnerabilities like CVE-2015-5576 that expose systems to significant risks.