[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-5123Date: (C)2015-07-14   (M)2024-03-06


Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1032890
BID-75710
GLSA-201508-01
HPSBMU03409
RHSA-2015:1235
SSRT102253
SUSE-SU-2015:1255
SUSE-SU-2015:1258
TA15-195A
VU#918568
http://blog.trendmicro.com/trendlabs-security-intelligence/new-zero-day-vulnerability-cve-2015-5123-in-adobe-flash-emerges-from-hacking-team-leak/
https://helpx.adobe.com/security/products/flash-player/apsa15-04.html
https://helpx.adobe.com/security/products/flash-player/apsb15-18.html
openSUSE-SU-2015:1267

CPE    72
cpe:/a:adobe:flash_player:11.2.202.429
cpe:/a:adobe:flash_player:11.1.111.8
cpe:/a:adobe:flash_player:11.1.115.7
cpe:/a:adobe:flash_player:11.1.115.54
...
CWE    1
CWE-416
OVAL    9
oval:org.secpod.oval:def:25327
oval:org.secpod.oval:def:25328
oval:org.secpod.oval:def:505515
oval:org.secpod.oval:def:25329
...

© SecPod Technologies