Description
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-8328 | Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438. |
References
History
No history.
Subscriptions
Adobe
Subscribe
Air
Subscribe
Air Sdk
Subscribe
Air Sdk \& Compiler
Subscribe
Flash Player
Subscribe
Apple
Subscribe
Iphone Os
Subscribe
Mac Os X
Subscribe
Google
Subscribe
Android
Subscribe
Linux
Subscribe
Linux Kernel
Subscribe
Microsoft
Subscribe
Windows
Subscribe
Redhat
Subscribe
Rhel Extras
Subscribe
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-06T08:20:42.390Z
Reserved: 2015-12-02T00:00:00.000Z
Link: CVE-2015-8446
No data.
Status : Modified
Published: 2015-12-10T06:00:10.387
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-8446
OpenCVE Enrichment
No data.
Weaknesses
EUVD