CVE-2015-3042
published 2015-04-14CVE-2015-3042: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute…
PriorityP268critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
36.81%
98.3th percentile
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3043.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | < 11.2.202.457 | 11.2.202.457 |
| adobe | flash_player | < 13.0.0.281 | 13.0.0.281 |
| adobe | flash_player | <= 11.2.202.451 | — |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | >= 14.0.0.125 < 17.0.0.169 | 17.0.0.169 |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_workstation_extension | — | — |
| opensuse | evergreen | — | — |
| opensuse | opensuse | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Flash content containing the degenerate PCRE conditional assertion pattern `(?(?)?)` or structurally equivalent zero-length assertion expressions that produce OP_BRAZERO before OP_CBRA in compiled PCRE bytecode, which causes an out-of-bounds ecode pointer jump. ↗
- →Look for PCRE bytecode sequences containing opcode 0x66 (OP_BRAZERO / decimal 102) immediately preceding opcode 0x5e (OP_CBRA / decimal 94) inside Flash SWF content, as this is the compiled form of the malicious regex. ↗
- →Monitor for exploitation of CVE-2015-3043 (memory corruption via PCRE zero-length assertion) in Adobe Flash Player versions before 13.0.0.281 (Windows/OS X) and before 11.2.202.457 (Linux); this CVE was actively exploited in the wild in April 2015. ↗
- →The out-of-bounds condition manifests as an ecode pointer jumping far outside the allocated heap buffer (e.g., from 0x600e0000dfe7 to 0x600e00013dea); heap-spray or large unexpected ecode delta in PCRE match execution within Flash processes is a strong indicator. ↗
- ·The NVD source references CVE-2015-3043 (not CVE-2015-3042); the exploit-db entry covers the PCRE zero-length assertion bug which is listed as a distinct vulnerability from CVE-2015-3042 in the NVD advisory. Confirm the correct CVE mapping before operationalizing these indicators. ↗
- ·The PoC crash was demonstrated specifically against Chrome/Flash on x64 Linux; exploitation reliability and bytecode offsets may differ on Windows/OS X Flash builds. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0354 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0352 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0360 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0353 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-3043 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0350 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-3038 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-3042 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0347 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-3041 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3042, and CVE-2015-3043.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-06
vendor_redhat·2015-04-14·CVSS 10.0
CVE-2015-0355 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-06
flash-plugin: multiple code execution issues fixed in APSB15-06
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-87rq-wh94-4x2j: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0354 [CRITICAL] GHSA-87rq-wh94-4x2j: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-gc3w-hppp-5vh9: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0360 [CRITICAL] GHSA-gc3w-hppp-5vh9: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-99jp-389h-929q: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0350 [CRITICAL] GHSA-99jp-389h-929q: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-r8v5-rf6g-q3m8: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-3038 [CRITICAL] GHSA-r8v5-rf6g-q3m8: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-r494-qvxr-557h: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0353 [CRITICAL] GHSA-r494-qvxr-557h: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-584x-j6hp-wjf7: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0355 [CRITICAL] GHSA-584x-j6hp-wjf7: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-68qr-58pp-42rr: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-3043 [CRITICAL] CWE-787 GHSA-68qr-58pp-42rr: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
GHSA
GHSA-989f-94hv-pcxc: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0347 [CRITICAL] GHSA-989f-94hv-pcxc: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-xj5f-4p5c-vxq5: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-3042 [CRITICAL] GHSA-xj5f-4p5c-vxq5: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3043.
GHSA
GHSA-7647-7jjc-5jw8: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-0352 [CRITICAL] GHSA-7647-7jjc-5jw8: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
GHSA
GHSA-hcpq-w7rj-wqc8: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-3041 [CRITICAL] GHSA-hcpq-w7rj-wqc8: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-0347: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0347 [CRITICAL] CVE-2015-0347: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-3042: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-3042 [CRITICAL] CVE-2015-3042: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3043.
OSV
CVE-2015-3041: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-3041 [CRITICAL] CVE-2015-3041: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-0354: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0354 [CRITICAL] CVE-2015-0354: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-3038: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-3038 [CRITICAL] CVE-2015-3038: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-0360: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0360 [CRITICAL] CVE-2015-0360: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-0353: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0353 [CRITICAL] CVE-2015-0353: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-0352: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0352 [CRITICAL] CVE-2015-0352: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-0350: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0350 [CRITICAL] CVE-2015-0350: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-0355: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-0355 [CRITICAL] CVE-2015-0355: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, and CVE-2015-3043.
OSV
CVE-2015-3043: Adobe Flash Player before 13
osv·2015-04-14·CVSS 10.0
CVE-2015-3043 [CRITICAL] CVE-2015-3043: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74062http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07https://www.exploit-db.com/exploits/37839/http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74062http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07https://www.exploit-db.com/exploits/37839/
2015-04-14
Published