CVE-2015-0312Double Free in Adobe Flash Player

CWE-415Double Free7 documents7 sources
Severity
9.3CRITICALNVD
EPSS
4.7%
top 10.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateMay 13

Description

Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDadobe/flash_player11.2.202.438+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3fv2-9g2f-63h7: Double free vulnerability in Adobe Flash Player before 132022-05-13
CVEList
CVE-2015-0312: Double free vulnerability in Adobe Flash Player before 132015-01-28
OSV
CVE-2015-0312: Double free vulnerability in Adobe Flash Player before 132015-01-28

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple critical vulnerabilities (APSA15-01)(APSB15-03)2015-01-26

💬Community

2
HackerOne
Race condition in workers may cause an exploitable double free by abusing bytearray.compress()2015-03-25
Bugzilla
CVE-2015-0311 CVE-2015-0312 flash-plugin: multiple critical vulnerabilities (APSA15-01)(APSB15-03)2015-01-23
CVE-2015-0312 — Double Free in Adobe Flash Player | cvebase