CVE-2015-3039

9 documents6 sources
Severity
10.0CRITICAL
EPSS
8.7%
top 7.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 14

Description

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-0358.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages7 packages

NVDadobe/flash_player11.2.202.451+16
Ubuntuflashplugin-nonfree< 11.2.202.457ubuntu0.14.04.1

Also affects: Enterprise Linux 5.0, 6.0, 6.6.z

Patches

🔴Vulnerability Details

4
GHSA
GHSA-chf4-4c79-55vc: Use-after-free vulnerability in Adobe Flash Player before 132022-05-14
Project0
Attacking ECMAScript Engines with Redefinition - Project Zero2015-08-01
CVEList
CVE-2015-3039: Use-after-free vulnerability in Adobe Flash Player before 132015-04-14
OSV
CVE-2015-3039: Use-after-free vulnerability in Adobe Flash Player before 132015-04-14

📋Vendor Advisories

4
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-062015-04-14
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-062015-04-14
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-062015-04-14
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-062015-04-14
CVE-2015-3039 (CRITICAL CVSS 10) | Use-after-free vulnerability in Ado | cvebase.io