← All CVEs

CVE-2015-5122

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-04-13Remediation due 2022-05-04

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

9.8
CVSS
94.0%
EPSS (exploit prob.)
100th
EPSS percentile
2015-07-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
adobeflash_player>= 13.0, <= 13.0.0.302
adobeflash_player>= 18.0, <= 18.0.0.203
adobeflash_player_desktop_runtime>= 18.0, <= 18.0.0.203
applemacosall versions
microsoftwindowsall versions
adobeflash_player>= 18.0, <= 18.0.0.204
linuxlinux_kernelall versions
adobeflash_player>= 18.0, <= 18.0.0.203
adobeflash_player>= 18.0, <= 18.0.0.203
microsoftwindows_8all versions
microsoftwindows_8.1all versions
adobeflash_player>= 11.0, <= 11.2.202.481
linuxlinux_kernelall versions
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_eus6.6
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0
opensuseevergreen11.4
suselinux_enterprise_desktop11
suselinux_enterprise_desktop11
suselinux_enterprise_desktop12
suselinux_enterprise_workstation_extension12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-5122