CVE-2015-0307
개요
CVE.org에서
Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.
CVSS (Common Vulnerability Scoring System) 점수 세부 사항
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v2 점수 분석
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| 기본 점수 | 4.3 | 8.5 | N/A |
| 공격 벡터 | Network | Network | N/A |
| 액세스 복잡성 | Medium | Low | N/A |
| 인증 | None | None | N/A |
| 기밀성에 미치는 영향 | Partial | Partial | N/A |
| 무결성에 미치는 영향 | None | None | N/A |
| 가용성에 미치는 영향 | None | Complete | N/A |
벡터
Red Hat: AV:N/AC:M/Au:N/C:P/I:N/A:N
NVD: AV:N/AC:L/Au:N/C:P/I:N/A:C