Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
21 Nov 2024, 02:22
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html - Mailing List, Third Party Advisory | |
References | () http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://secunia.com/advisories/62528 - Broken Link | |
References | () http://secunia.com/advisories/62777 - Broken Link | |
References | () http://secunia.com/advisories/62895 - Broken Link | |
References | () http://www.osvdb.org/117853 - Broken Link | |
References | () http://www.securityfocus.com/bid/72429 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1031686 - Broken Link, Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 - Third Party Advisory, VDB Entry | |
References | () https://helpx.adobe.com/security/products/flash-player/apsa15-02.html - Vendor Advisory | |
References | () https://helpx.adobe.com/security/products/flash-player/apsb15-04.html - Broken Link | |
References | () https://technet.microsoft.com/library/security/2755801 - Patch, Vendor Advisory | |
References | () https://www.exploit-db.com/exploits/36579/ - Exploit, Third Party Advisory, VDB Entry |
02 Jul 2024, 17:41
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:* cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:* |
cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:-:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* |
CWE | CWE-416 | |
First Time |
Microsoft windows 8.1
Suse Microsoft windows Rt 8.1 Microsoft windows 10 1507 Microsoft internet Explorer Microsoft windows Server 2012 Suse linux Enterprise Desktop Opensuse opensuse Microsoft windows Rt Opensuse Microsoft windows 8 Suse linux Enterprise Workstation Extension Opensuse evergreen Microsoft edge |
|
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html - Mailing List, Third Party Advisory | |
References | () http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://secunia.com/advisories/62528 - Broken Link | |
References | () http://secunia.com/advisories/62777 - Broken Link | |
References | () http://secunia.com/advisories/62895 - Broken Link | |
References | () http://www.osvdb.org/117853 - Broken Link | |
References | () http://www.securityfocus.com/bid/72429 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1031686 - Broken Link, Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 - Third Party Advisory, VDB Entry | |
References | () https://helpx.adobe.com/security/products/flash-player/apsb15-04.html - Broken Link | |
References | () https://technet.microsoft.com/library/security/2755801 - Patch, Vendor Advisory | |
References | () https://www.exploit-db.com/exploits/36579/ - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2015-02-02 19:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-0313
Mitre link : CVE-2015-0313
CVE.ORG link : CVE-2015-0313
JSON object : View
Products Affected
suse
- linux_enterprise_workstation_extension
- linux_enterprise_desktop
microsoft
- windows_8.1
- windows_10_1507
- internet_explorer
- windows_rt
- windows
- edge
- windows_8
- windows_rt_8.1
- windows_server_2012
opensuse
- opensuse
- evergreen
adobe
- flash_player
linux
- linux_kernel
apple
- mac_os_x
CWE
CWE-416
Use After Free