First published: Sun Oct 18 2015(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7629, CVE-2015-7631, CVE-2015-7636, CVE-2015-7637, CVE-2015-7638, CVE-2015-7639, CVE-2015-7640, CVE-2015-7641, CVE-2015-7642, CVE-2015-7643, and CVE-2015-7644.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | <=19.0.0.190 | |
Adobe AIR SDK and Compiler | <=19.0.0.190 | |
Adobe AIR SDK & Compiler | <=19.0.0.190 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=19.0.0.185 | |
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.521 | |
Linux Kernel | ||
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7635 is classified as critical due to its potential to allow attackers to execute arbitrary code remotely.
To fix CVE-2015-7635, users should update Adobe Flash Player and Adobe AIR to the latest versions available.
CVE-2015-7635 affects Adobe Flash Player versions before 18.0.0.252 and 19.x before 19.0.0.207, as well as various versions of Adobe AIR before 19.0.0.213.
Yes, Linux users are affected if they are using Adobe Flash Player versions before 11.2.202.535.
The potential impacts of CVE-2015-7635 include unauthorized access, data theft, and full system compromise due to arbitrary code execution.