CVE-2015-0315
published 2015-02-06CVE-2015-0315: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on…
PriorityP351critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.62%
94.9th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0320, and CVE-2015-0322.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | < 11.2.202.442 | 11.2.202.442 |
| adobe | flash_player | < 13.0.0.269 | 13.0.0.269 |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | <= 11.2.202.440 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | >= 14.0.0.125 < 16.0.0.305 | 16.0.0.305 |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| opensuse | evergreen | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xww9-82cx-c8c3: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2015-0315 [CRITICAL] GHSA-xww9-82cx-c8c3: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0320, and CVE-2015-0322.
GHSA
GHSA-35mf-vj2p-cr8q: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2015-0320 [CRITICAL] GHSA-35mf-vj2p-cr8q: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.
GHSA
GHSA-rrq2-j6vp-346q: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2015-0322 [CRITICAL] GHSA-rrq2-j6vp-346q: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0320.
GHSA
GHSA-rr27-273m-v696: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2015-0331 [CRITICAL] GHSA-rr27-273m-v696: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
GHSA
GHSA-fg66-4vpm-36cx: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-0313 [CRITICAL] CWE-416 GHSA-fg66-4vpm-36cx: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
OSV
CVE-2015-0331: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-02-21·CVSS 9.8
CVE-2015-0331 [CRITICAL] CVE-2015-0331: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
OSV
CVE-2015-0315: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-02-06·CVSS 9.8
CVE-2015-0315 [CRITICAL] CVE-2015-0315: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0320, and CVE-2015-0322.
OSV
CVE-2015-0320: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-02-06·CVSS 9.8
CVE-2015-0320 [CRITICAL] CVE-2015-0320: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.
OSV
CVE-2015-0322: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-02-06·CVSS 9.8
CVE-2015-0322 [CRITICAL] CVE-2015-0322: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0320.
OSV
CVE-2015-0313: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-02-02·CVSS 9.8
CVE-2015-0313 [CRITICAL] CVE-2015-0313: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)
vendor_redhat·2015-02-04·CVSS 9.8
CVE-2015-0331 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-04)
flash-plugin: multiple code execution flaws (APSB15-04)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)
vendor_redhat·2015-02-04·CVSS 9.8
CVE-2015-0322 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-04)
flash-plugin: multiple code execution flaws (APSB15-04)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0320.
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)
vendor_redhat·2015-02-04·CVSS 9.8
CVE-2015-0315 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-04)
flash-plugin: multiple code execution flaws (APSB15-04)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0320, and CVE-2015-0322.
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)
vendor_redhat·2015-02-04·CVSS 9.8
CVE-2015-0320 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-04)
flash-plugin: multiple code execution flaws (APSB15-04)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.
Red Hat
flash-plugin: use-after-free leading to code execution (APSB15-04)
vendor_redhat·2015-02-02·CVSS 9.8
CVE-2015-0313 [CRITICAL] CWE-416 flash-plugin: use-after-free leading to code execution (APSB15-04)
flash-plugin: use-after-free leading to code execution (APSB15-04)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Package: flash-plugin (Red Hat Enterprise Linux 5) - Not affected
Package: flash-plugin (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan.
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry, a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have already been identified, impacting various common software applicati
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
## Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan .
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry , a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have
HackerOne
Use after free during the StageVideoAvailabilityEvent can result in arbitrary code execution
hackerone·2015-03-25·CVSS 10.0
CVE-2015-0315 [CRITICAL] Use after free during the StageVideoAvailabilityEvent can result in arbitrary code execution
Use after free during the StageVideoAvailabilityEvent can result in arbitrary code execution
An attacker can register the StageVideoAvailabilityEvent and have the SWF movie reloaded at the same time with LoadMovie. During this process, an object may be freed allowing the attacker to take control of the code flow.
Identified as CVE-2015-0315, and reported to Adobe via Chrome VRP:
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html
Original report with an exploit for Chrome:
https://code.google.com/p/chromium/issues/detail?id=429276
Bugzilla
flash-plugin: multiple code execution flaws (APSB15-04)
bugzilla·2015-02-06·CVSS 9.8
CVE-2015-0313 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-04)
flash-plugin: multiple code execution flaws (APSB15-04)
Adobe has released Flash Player 11.2.202.442 for Linux to correct the following flaws:
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, CVE-2015-0322).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, CVE-2015-0329, CVE-2015-0330).
These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2015-0317, CVE-2015-0319).
These updates resolve heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-0323, CVE-2015-0327).
These updates resolve a buffer overflow vulnerability that could lead to cod
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0140.htmlhttp://secunia.com/advisories/62777http://secunia.com/advisories/62886http://secunia.com/advisories/62895http://security.gentoo.org/glsa/glsa-201502-02.xmlhttp://www.securityfocus.com/bid/72514http://www.securitytracker.com/id/1031706https://exchange.xforce.ibmcloud.com/vulnerabilities/100697https://helpx.adobe.com/security/products/flash-player/apsb15-04.htmlhttps://technet.microsoft.com/library/security/2755801http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0140.htmlhttp://secunia.com/advisories/62777http://secunia.com/advisories/62886http://secunia.com/advisories/62895http://security.gentoo.org/glsa/glsa-201502-02.xmlhttp://www.securityfocus.com/bid/72514http://www.securitytracker.com/id/1031706https://exchange.xforce.ibmcloud.com/vulnerabilities/100697https://helpx.adobe.com/security/products/flash-player/apsb15-04.htmlhttps://technet.microsoft.com/library/security/2755801
2015-02-06
Published