CVE-2015-0308
published 2015-01-13CVE-2015-0308: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.23%
93.7th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allows attackers to execute arbitrary code via unspecified vectors.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 15.0.0.356 | — |
| adobe | adobe_air_sdk | <= 15.0.0.356 | — |
| adobe | adobe_air_sdk_and_compiler | <= 15.0.0.356 | — |
| adobe | flash_player | <= 13.0.0.259 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: Multiple code-execution flaws (APSB15-01)
vendor_redhat·2015-01-13·CVSS 10.0
CVE-2015-0308 [CRITICAL] CWE-122 flash-plugin: Multiple code-execution flaws (APSB15-01)
flash-plugin: Multiple code-execution flaws (APSB15-01)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allows attackers to execute arbitrary code via unspecified vectors.
GHSA
GHSA-jj79-pvfh-j7f7: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2015-0308 [HIGH] GHSA-jj79-pvfh-j7f7: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2015-0308: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-01-13·CVSS 10.0
CVE-2015-0308 [CRITICAL] CVE-2015-0308: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan.
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry, a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have already been identified, impacting various common software applicati
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
## Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan .
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry , a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have
Bugzilla
CVE-2015-0303 CVE-2015-0306 CVE-2015-0304 CVE-2015-0309 CVE-2015-0305 CVE-2015-0308 flash-plugin: Multiple code-execution flaws (APSB15-01)
bugzilla·2015-01-14·CVSS 10.0
CVE-2015-0303 [CRITICAL] CVE-2015-0303 CVE-2015-0306 CVE-2015-0304 CVE-2015-0309 CVE-2015-0305 CVE-2015-0308 flash-plugin: Multiple code-execution flaws (APSB15-01)
CVE-2015-0303 CVE-2015-0306 CVE-2015-0304 CVE-2015-0309 CVE-2015-0305 CVE-2015-0308 flash-plugin: Multiple code-execution flaws (APSB15-01)
Adobe has released Flash Player 11.2.202.429 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-0303, CVE-2015-0306).
* These updates resolve heap-based buffer overflow vulnerabilities that could lead to code execution (CVE-2015-0304, CVE-2015-0309).
* These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2015-0305).
* These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2015-0308).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb15-01.html
Discu
http://helpx.adobe.com/security/products/flash-player/apsb15-01.htmlhttp://secunia.com/advisories/62177http://secunia.com/advisories/62187http://secunia.com/advisories/62252http://secunia.com/advisories/62371http://secunia.com/advisories/62740http://security.gentoo.org/glsa/glsa-201502-02.xmlhttp://www.securityfocus.com/bid/72039http://www.securitytracker.com/id/1031525https://exchange.xforce.ibmcloud.com/vulnerabilities/99989http://helpx.adobe.com/security/products/flash-player/apsb15-01.htmlhttp://secunia.com/advisories/62177http://secunia.com/advisories/62187http://secunia.com/advisories/62252http://secunia.com/advisories/62371http://secunia.com/advisories/62740http://security.gentoo.org/glsa/glsa-201502-02.xmlhttp://www.securityfocus.com/bid/72039http://www.securitytracker.com/id/1031525https://exchange.xforce.ibmcloud.com/vulnerabilities/99989
2015-01-13
Published