CVE-2015-7655: Use After Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted actionExtends arguments, a different vulnerability than CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, CVE-2015-8044, and CVE-2015-8046.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7655?
CVE-2015-7655 is categorized as a critical vulnerability due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2015-7655?
To mitigate CVE-2015-7655, upgrade Adobe Flash Player to version 18.0.0.261 or later and Adobe AIR to version 19.0.0.241 or later.
Which versions of Adobe Flash Player are affected by CVE-2015-7655?
CVE-2015-7655 affects Adobe Flash Player versions before 18.0.0.261 and 19.x before 19.0.0.245.
Are there any operating systems that are vulnerable to CVE-2015-7655?
CVE-2015-7655 affects Adobe Flash Player and AIR on Windows, OS X, and Linux systems with specific versions.
What types of attacks can CVE-2015-7655 enable?
CVE-2015-7655 can enable remote code execution attacks, allowing an attacker to take control of an affected system.