CVE-2015-5123
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 | |
| Version 5.0 | |
| Version 6.6 | |
| Version 5.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4 | |
| Version 11 sp3 | |
| Version 12 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.0 to 11.2.202.481 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.0 to 18.0.0.203 | |
| From 18.0 to 18.0.0.203 |
| Running on/with | Platform Versions |
|---|---|
Apple Macos | All versions |
Microsoft Windows | All versions |
References (30)
Source: psirt@adobe.com
Broken LinkThird Party Advisory
Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Mailing ListThird Party Advisory
Source: psirt@adobe.com
Third Party AdvisoryUS Government Resource
Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
Third Party AdvisoryUS Government Resource
Source: psirt@adobe.com
Broken LinkThird Party Advisory
Source: psirt@adobe.com
Broken LinkVendor Advisory
Source: psirt@adobe.com
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Issue Tracking
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.