This script is Copyright (C) 2015-2017 Tenable Network Security, Inc.
The remote Windows host has a browser plugin installed that is
affected by multiple vulnerabilities.
The remote Windows host is missing KB3099406. It is, therefore,
affected by multiple vulnerabilities :
- An unspecified vulnerability exists related to the
defense-in-depth feature in the Flash Broker API. No
other details are available. (CVE-2015-5569)
- Multiple unspecified memory corruption issues exist due
to improper validation of user-supplied input. A remote
attacker can exploit this to execute arbitrary code.
(CVE-2015-7625, CVE-2015-7626, CVE-2015-7627,
CVE-2015-7630, CVE-2015-7633, CVE-2015-7634)
- A unspecified vulnerability exists that can be exploited
by a remote attacker to bypass the same-origin policy,
allowing the disclosure of sensitive information.
- Multiple unspecified use-after-free errors exist that
can be exploited by a remote attacker to deference
already freed memory, potentially allowing the
execution of arbitrary code. (CVE-2015-7629,
CVE-2015-7631, CVE-2015-7643, CVE-2015-7644)
- An unspecified buffer overflow condition exists due to
improper validation of user-supplied input. An attacker
can exploit this to execute arbitrary code.
See also :
Install Microsoft KB3099406.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 6.9
Public Exploit Available : false
Nessus Plugin ID: 86371 ()
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now