CVE-2015-3113
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product is end-of-life and should be disconnected if still in use.
Added 2022-04-13Remediation due 2022-05-04
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
9.8
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2015-06-23
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-787CWE-122
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | flash_player | < 13.0.0.296 |
| adobe | flash_player | >= 14.0.0.125, < 18.0.0.194 |
| apple | mac_os_x | all versions |
| microsoft | windows | all versions |
| adobe | flash_player | < 11.2.202.468 |
| linux | linux_kernel | all versions |
| opensuse | evergreen | 11.4 |
| opensuse | opensuse | 13.1 |
| opensuse | opensuse | 13.2 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_workstation_extension | 12 |
| hp | insight_orchestration | < 7.5.0 |
| hp | system_management_homepage | < 7.5.0 |
| hp | systems_insight_manager | < 7.5 |
| hp | version_control_agent | < 7.5.0 |
| hp | version_control_repository_manager | < 7.5.0 |
| hp | version_control_repository_manager | 7.6 |
| hp | virtual_connect_enterprise_manager | < 7.5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 6.6 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00002.html
- http://marc.info/?l=bugtraq&m=144050155601375&w=2
- http://rhn.redhat.com/errata/RHSA-2015-1184.html
- http://www.securityfocus.com/bid/75371
- http://www.securitytracker.com/id/1032696
- https://bugzilla.redhat.com/show_bug.cgi?id=1235036
- https://bugzilla.suse.com/show_bug.cgi?id=935701
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952467
- https://helpx.adobe.com/security/products/flash-player/apsb15-14.html
- https://security.gentoo.org/glsa/201507-13
- https://www.suse.com/security/cve/CVE-2015-3113.html
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00002.html
- http://marc.info/?l=bugtraq&m=144050155601375&w=2
- http://rhn.redhat.com/errata/RHSA-2015-1184.html
- http://www.securityfocus.com/bid/75371
- http://www.securitytracker.com/id/1032696
- https://bugzilla.redhat.com/show_bug.cgi?id=1235036
- https://bugzilla.suse.com/show_bug.cgi?id=935701
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952467
- https://helpx.adobe.com/security/products/flash-player/apsb15-14.html
- https://security.gentoo.org/glsa/201507-13
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-3113