Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-5571

Опубликовано: 22 сент. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.

РелизСтатусПримечание
devel

released

1:20150921.1-0wily1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:20150921.1-0trusty1]]
precise

released

1:20150921.1-0precise1
trusty

released

1:20150921.1-0trusty1
trusty/esm

DNE

trusty was released [1:20150921.1-0trusty1]
upstream

released

11.2.202.521
vivid

released

1:20150921.1-0vivid1

Показывать по

РелизСтатусПримечание
devel

released

11.2.202.521ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [11.2.202.521ubuntu0.14.04.1]]
precise

released

11.2.202.521ubuntu0.12.04.1
trusty

released

11.2.202.521ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [11.2.202.521ubuntu0.14.04.1]
upstream

released

11.2.202.521
vivid

released

11.2.202.521ubuntu0.15.04.1

Показывать по

EPSS

Процентиль: 88%
0.03336
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.

nvd
почти 11 лет назад

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.

github
около 4 лет назад

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.

fstec
почти 11 лет назад

Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю получить доступ к защищаемой информации

suse-cvrf
почти 11 лет назад

Security update for flash-player

EPSS

Процентиль: 88%
0.03336
Низкий

4.3 Medium

CVSS2