CVE-2015-7631 is a critical use-after-free vulnerability in Adobe Flash Player, AIR, and AIR SDK across Windows, OS X, and Linux platforms. This flaw allows attackers to execute arbitrary code by manipulating a TextLine object with a crafted validity property. With a CVSS score of 9.3, this vulnerability is highly severe, requiring no authentication and having a medium attack complexity, but leading to complete compromise of confidentiality, integrity, and availability. While no public exploits or Metasploit modules are currently available, and community discussion is minimal, the high FAUCET Risk Score of 82/100 indicates its potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 19.0.0.190CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
<= 11.2.202.521CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 19.0.0.190CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
<= 19.0.0.190CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.