CVE-2015-0346
published 2015-04-14CVE-2015-0346: Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux…
PriorityP350critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
10.38%
95.2th percentile
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | <= 11.2.202.451 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7vvf-ghq4-pw24: Double free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-0359 [CRITICAL] GHSA-7vvf-ghq4-pw24: Double free vulnerability in Adobe Flash Player before 13
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
GHSA
GHSA-r6j8-xrxq-g7wx: Double free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0346 [CRITICAL] GHSA-r6j8-xrxq-g7wx: Double free vulnerability in Adobe Flash Player before 13
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359.
OSV
CVE-2015-0359: Double free vulnerability in Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0359 [CRITICAL] CVE-2015-0359: Double free vulnerability in Adobe Flash Player before 13
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
OSV
CVE-2015-0346: Double free vulnerability in Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0346 [CRITICAL] CVE-2015-0346: Double free vulnerability in Adobe Flash Player before 13
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359.
VulnCheck
Adobe Flash Player Double Free
vulncheck·2015·CVSS 10.0
CVE-2015-0359 [CRITICAL] Adobe Flash Player Double Free
Adobe Flash Player Double Free
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.recordedfuture.com/blog/top-vulnerabilities-2015
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0359 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0346 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359.
No detection rules found.
No public exploits indexed.
HackerOne
Double free vulnerability in Flash Player Settings Manager (CVE-2015-0346)
hackerone·2019-10-18·CVSS 10.0
CVE-2015-0346 [CRITICAL] Double free vulnerability in Flash Player Settings Manager (CVE-2015-0346)
Double free vulnerability in Flash Player Settings Manager (CVE-2015-0346)
This was patched by https://helpx.adobe.com/security/products/flash-player/apsb15-06.html , described as a "double-free vulnerabilit[y] that could lead to code execution".
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-06
bugzilla·2015-04-15·CVSS 10.0
CVE-2015-0347 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Security Bulletin APSB15-06 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-06:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043).
These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2015-0356).
These updates resolve a buffer overflow vulnerability that could lead to code execution (CVE-2015-0348).
These updates resolve use-after-free vulnerabilit
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74067http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74067http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07
2015-04-14
Published