Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-0359Double Free in Adobe Flash Player

17 documents10 sources
Severity
10.0CRITICALNVD
EPSS
88.6%
top 0.49%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 14
Latest updateMay 17

Description

Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages6 packages

Also affects: Enterprise Linux 5.0, 6.0, 6.6.z

Patches

🔴Vulnerability Details

5
GHSA
GHSA-7vvf-ghq4-pw24: Double free vulnerability in Adobe Flash Player before 132022-05-17
GHSA
GHSA-r6j8-xrxq-g7wx: Double free vulnerability in Adobe Flash Player before 132022-05-14
OSV
CVE-2015-0359: Double free vulnerability in Adobe Flash Player before 132015-04-14
OSV
CVE-2015-0346: Double free vulnerability in Adobe Flash Player before 132015-04-14
VulnCheck
Adobe Flash Player Double Free2015

💥Exploits & PoCs

2
Exploit-DB
Adobe Flash Player - domainMemory ByteArray Use-After-Free (Metasploit)2015-05-08
Metasploit
Adobe Flash Player domainMemory ByteArray Use After Free

📋Vendor Advisories

2
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-062015-04-14
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-062015-04-14

🕵️Threat Intelligence

5
Fortinet
The Definition and Examples of Exploit Kits | Fortinet Blog2022-01-27
Unit42
Understanding Flash Exploitation and the Alleged CVE-2015-0359 Exploit2015-06-01
Unit42
Understanding Flash Exploitation and the Alleged CVE-2015-0359 Exploit2015-06-01
Unit42
The Latest Flash UAF Vulnerabilities in Exploit Kits2015-05-28
Unit42
The Latest Flash UAF Vulnerabilities in Exploit Kits2015-05-28

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-062015-04-15