peter bassill · operator
$ cve CVE-2015-5119 JSON

CVE-2015-5119 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 99.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.33% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2015-07-08
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Use-After-Free Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (14)

VendorProduct
adobeflash player
applemac os x
linuxlinux kernel
microsoftwindows
opensuseevergreen
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server from rhui
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise workstation extension

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD