← All CVEs

CVE-2015-5123

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-04-13Remediation due 2022-05-04

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

9.8
CVSS
18.8%
EPSS (exploit prob.)
97th
EPSS percentile
2015-07-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_eus6.6
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0
opensuseevergreen11.4
suselinux_enterprise_desktop11
suselinux_enterprise_desktop11
suselinux_enterprise_desktop12
suselinux_enterprise_workstation_extension12
adobeflash_player>= 11.0, <= 11.2.202.481
linuxlinux_kernelall versions
adobeflash_player>= 13.0, <= 13.0.0.302
adobeflash_player>= 18.0, <= 18.0.0.203
adobeflash_player_desktop_runtime>= 18.0, <= 18.0.0.203
applemacosall versions
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-5123