CVE-2015-0320Use After Free in Adobe Flash Player

CWE-416Use After Free24 documents7 sources
Severity
10.0CRITICALNVD
NVD9.8OSV9.8
EPSS
3.9%
top 11.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 17

Description

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages6 packages

NVDadobe/flash_player14.0.0.12516.0.0.305+18
NVDopensuse/opensuse13.1, 13.2+1

Patches

🔴Vulnerability Details

10
GHSA
GHSA-xww9-82cx-c8c3: Use-after-free vulnerability in Adobe Flash Player before 132022-05-17
GHSA
GHSA-35mf-vj2p-cr8q: Use-after-free vulnerability in Adobe Flash Player before 132022-05-17
GHSA
GHSA-rrq2-j6vp-346q: Use-after-free vulnerability in Adobe Flash Player before 132022-05-17
GHSA
GHSA-rr27-273m-v696: Use-after-free vulnerability in Adobe Flash Player before 132022-05-17
GHSA
GHSA-fg66-4vpm-36cx: Use-after-free vulnerability in Adobe Flash Player before 132022-05-17

📋Vendor Advisories

5
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)2015-02-04
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)2015-02-04
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)2015-02-04
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)2015-02-04
Red Hat
flash-plugin: use-after-free leading to code execution (APSB15-04)2015-02-02

🕵️Threat Intelligence

2
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities2015-03-17
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities2015-03-17

💬Community

2
HackerOne
Use After Free in Flash MessageChannel.send can cause arbitrary code execution2015-03-25
Bugzilla
flash-plugin: multiple code execution flaws (APSB15-04)2015-02-06