CVE-2015-0337
published 2015-03-13CVE-2015-0337: Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
4.42%
90.3th percentile
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 11.2.202.442 | — |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cpwg-j57v-cvjg: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2015-0337 [MEDIUM] GHSA-cpwg-j57v-cvjg: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
OSV
CVE-2015-0337: Adobe Flash Player before 13
osv·2015-03-13·CVSS 5.0
CVE-2015-0337 [MEDIUM] CVE-2015-0337: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Red Hat
flash-plugin: cross-domain policy bypass (APSB15-05)
vendor_redhat·2015-03-12·CVSS 5.0
CVE-2015-0337 [MEDIUM] flash-plugin: cross-domain policy bypass (APSB15-05)
flash-plugin: cross-domain policy bypass (APSB15-05)
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
No detection rules found.
No public exploits indexed.
HackerOne
Flash Cross Domain Policy Bypass by Using File Upload and Redirection - only in Chrome
hackerone·2015-05-06·CVSS 5.0
CVE-2015-0337 [MEDIUM] Flash Cross Domain Policy Bypass by Using File Upload and Redirection - only in Chrome
Flash Cross Domain Policy Bypass by Using File Upload and Redirection - only in Chrome
CVE-2015-0337: https://helpx.adobe.com/security/products/flash-player/apsb15-05.html
+
https://code.google.com/p/chromium/issues/detail?can=2&start=0&num=100&q=&groupby=&sort=&id=425280
==VULNERABILITY DETAILS==
It is possible to bypass Flash Cross Domain policy in Google Chrome to read other websites' contents after a user uploads a file to a destination that redirects the user to the target website. It is also possible to send a file upload request to a target website without checking the cross domain policy by using an open redirect with status code of 307 (or 308).
This attack works as follows:
1- The "FileReference" class provides a means to upload file to a target server in ActionScript.
2- It ac
Bugzilla
CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05)
bugzilla·2015-03-13·CVSS 5.0
CVE-2015-0337 [MEDIUM] CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05)
CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05)
Adobe has released Flash Player 11.2.202.451 for Linux via APSB15-05 to correct the following flaw:
* These updates resolve a vulnerability that could lead to a cross-domain policy bypass (CVE-2015-0337).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-05.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0697 https://rhn.redhat.com/errata/RHSA-2015-0697.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0697.htmlhttp://www.securitytracker.com/id/1031922https://helpx.adobe.com/security/products/flash-player/apsb15-05.htmlhttps://security.gentoo.org/glsa/201503-09http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0697.htmlhttp://www.securitytracker.com/id/1031922https://helpx.adobe.com/security/products/flash-player/apsb15-05.htmlhttps://security.gentoo.org/glsa/201503-09
2015-03-13
Published