CVE-2015-3129 is a critical use-after-free vulnerability affecting multiple versions of Adobe Flash Player, Adobe AIR, and related SDKs across Windows, OS X, and Linux platforms. This flaw allows an unauthenticated, remote attacker to execute arbitrary code with maximum impact on confidentiality, integrity, and availability. While the vulnerability carries a CVSS score of 10.0 and a high FAUCET Risk Score of 90/100, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.289CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
14.0.0.125CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:* | ||
14.0.0.145CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:* | ||
14.0.0.176CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:* | ||
14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.