First published: Wed Sep 09 2015(Updated: )
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Shockwave Player | <=12.1.9.160 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6680 is classified as a critical vulnerability due to its potential for arbitrary code execution and denial of service.
To fix CVE-2015-6680, update Adobe Shockwave Player to version 12.2.0.162 or later.
The risks associated with CVE-2015-6680 include possible arbitrary code execution and system crashes from memory corruption.
Adobe Shockwave Player versions prior to 12.2.0.162 are affected by CVE-2015-6680.
If you cannot update to fix CVE-2015-6680, consider disabling or uninstalling Adobe Shockwave Player to mitigate risk.