← Back

CVE-2015-5122

nvd nist
Published: Jul 14, 2015Modified: Apr 21, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

Affected (19)

Show all products
2 products
Flash Player
Flash Player Desktop Runtime
4 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Eus
Enterprise Linux Workstation
1 product
Evergreen
2 products
Linux Enterprise Desktop
Configuration A
3 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Adobe
From 18.0 to 18.0.0.203
From 13.0 to 13.0.0.302
From 18.0 to 18.0.0.203
Running on/withPlatform Versions
Apple
Macos
All versions
Microsoft
Windows
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 18.0 to 18.0.0.204
Configuration C
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Adobe
From 18.0 to 18.0.0.203
From 18.0 to 18.0.0.203
Running on/withPlatform Versions
Microsoft
Windows 8
All versions
Microsoft
Windows 8.1
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 11.0 to 11.2.202.481
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Configuration E
7 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 5.0
Version 6.0
Redhat
Version 5.0
Version 6.0
Version 6.6
Redhat
Version 5.0
Version 6.0
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.4
Suse
Version 11 sp3
Version 11 sp4
Version 12
Version 12

References (42)

Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Third Party Advisory
Source: psirt@adobe.com
Third Party AdvisoryUS Government Resource
Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
Third Party AdvisoryUS Government Resource
Source: psirt@adobe.com
Broken LinkVendor Advisory
Source: psirt@adobe.com
Broken LinkVendor Advisory
Source: psirt@adobe.com
Broken LinkThird Party Advisory
Source: psirt@adobe.com
Broken LinkThird Party Advisory
Source: psirt@adobe.com
Third Party Advisory
Source: psirt@adobe.com
ExploitThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Issue Tracking
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.