CVE-2015-0358
published 2015-04-14CVE-2015-0358: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on…
PriorityP350critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
10.38%
95.2th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-3039.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 11.2.202.451 | — |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chf4-4c79-55vc: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-3039 [CRITICAL] GHSA-chf4-4c79-55vc: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-0358.
GHSA
GHSA-5w79-g7cc-6jwx: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0349 [CRITICAL] GHSA-5w79-g7cc-6jwx: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0351, CVE-2015-0358, and CVE-2015-3039.
GHSA
GHSA-63rx-qv87-g36c: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0358 [CRITICAL] GHSA-63rx-qv87-g36c: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-3039.
GHSA
GHSA-mr8p-cqx3-hgmp: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0351 [CRITICAL] GHSA-mr8p-cqx3-hgmp: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0358, and CVE-2015-3039.
OSV
CVE-2015-3039: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-3039 [CRITICAL] CVE-2015-3039: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-0358.
OSV
CVE-2015-0351: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0351 [CRITICAL] CVE-2015-0351: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0358, and CVE-2015-3039.
OSV
CVE-2015-0358: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0358 [CRITICAL] CVE-2015-0358: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-3039.
OSV
CVE-2015-0349: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0349 [CRITICAL] CVE-2015-0349: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0351, CVE-2015-0358, and CVE-2015-3039.
VulnCheck
Adobe Flash Player Use After Free
vulncheck·2015·CVSS 10.0
CVE-2015-0349 [CRITICAL] Adobe Flash Player Use After Free
Adobe Flash Player Use After Free
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0351, CVE-2015-0358, and CVE-2015-3039.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://resources.infosecinstitute.com/topic/the-hacking-team-hack-when-hackers-have-become-the-target/
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0358 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-3039.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-3039 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-0358.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0349 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0351, CVE-2015-0358, and CVE-2015-3039.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0351 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0358, and CVE-2015-3039.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74064http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74064http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07
2015-04-14
Published