Lucene search

K
cve[email protected]CVE-2015-5122
HistoryJul 14, 2015 - 10:59 a.m.

CVE-2015-5122

2015-07-1410:59:00
web.nvd.nist.gov
868
In Wild
cve
adobe flash player
vulnerability
use-after-free
memory corruption
remote code execution
nvd
as3
actionscript 3

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.6 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

Affected configurations

NVD
Node
adobeflash_playerRange13.013.0.0.302esr
OR
adobeflash_playerRange18.018.0.0.203chrome
OR
adobeflash_player_desktop_runtimeRange18.018.0.0.203
AND
applemacosMatch-
OR
microsoftwindowsMatch-
Node
adobeflash_playerRange18.018.0.0.204chrome
AND
linuxlinux_kernelMatch-
Node
adobeflash_playerRange18.018.0.0.203internet_explorer_10
OR
adobeflash_playerRange18.018.0.0.203internet_explorer_11
AND
microsoftwindows_8Match-
OR
microsoftwindows_8.1Match-
Node
adobeflash_playerRange11.011.2.202.481
AND
linuxlinux_kernelMatch-
Node
redhatenterprise_linux_desktopMatch5.0
OR
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_serverMatch5.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_server_eusMatch6.6
OR
redhatenterprise_linux_workstationMatch5.0
OR
redhatenterprise_linux_workstationMatch6.0
Node
opensuseevergreenMatch11.4
OR
suselinux_enterprise_desktopMatch11sp3
OR
suselinux_enterprise_desktopMatch11sp4
OR
suselinux_enterprise_desktopMatch12
OR
suselinux_enterprise_workstation_extensionMatch12

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.6 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%