CVE-2015-0342
published 2015-03-13CVE-2015-0342: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.74%
93.2th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0341.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 11.2.202.442 | — |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-05
vendor_redhat·2015-03-12·CVSS 10.0
CVE-2015-0341 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-05
flash-plugin: multiple code execution issues fixed in APSB15-05
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0342.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-05
vendor_redhat·2015-03-12·CVSS 10.0
CVE-2015-0342 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-05
flash-plugin: multiple code execution issues fixed in APSB15-05
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0341.
GHSA
GHSA-x556-4hr9-r4vf: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-0341 [CRITICAL] GHSA-x556-4hr9-r4vf: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0342.
GHSA
GHSA-g244-7952-w558: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-0342 [CRITICAL] GHSA-g244-7952-w558: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0341.
OSV
CVE-2015-0342: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-03-13·CVSS 10.0
CVE-2015-0342 [CRITICAL] CVE-2015-0342: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0341.
OSV
CVE-2015-0341: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-03-13·CVSS 10.0
CVE-2015-0341 [CRITICAL] CVE-2015-0341: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0342.
No detection rules found.
No public exploits indexed.
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-05
bugzilla·2015-03-13·CVSS 10.0
CVE-2015-0332 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-05
flash-plugin: multiple code execution issues fixed in APSB15-05
Adobe Security Bulletin APSB15-05 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-05:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339).
These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2015-0334, CVE-2015-0336).
These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2015-0338).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-0341, CVE-2015-0342).
External Referenc
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan.
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry, a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have already been identified, impacting various common software applicati
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
## Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan .
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry , a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0697.htmlhttp://www.securitytracker.com/id/1031922https://helpx.adobe.com/security/products/flash-player/apsb15-05.htmlhttps://security.gentoo.org/glsa/201503-09http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0697.htmlhttp://www.securitytracker.com/id/1031922https://helpx.adobe.com/security/products/flash-player/apsb15-05.htmlhttps://security.gentoo.org/glsa/201503-09
2015-03-13
Published