CVE-2015-3088
published 2015-05-13CVE-2015-3088: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on…
PriorityP274critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
61.98%
99.1th percentile
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 17.0.0.144 | — |
| adobe | air_sdk | <= 17.0.0.144 | — |
| adobe | air_sdk_compiler | <= 17.0.0.144 | — |
| adobe | flash_player | <= 11.2.202.475 | — |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect calls to AVSS.setSubscribedTags, AVSS.setCuePointTags, or AVSS.setSubscribedTagsForBackgroundManifest from within a custom toString() override on an array element — the exploit triggers the heap overflow by re-invoking setSubscribedTags with a smaller array inside a toString callback. ↗
- →Look for ActionScript instantiation of flash.media.AVSegmentedSource combined with large array allocations (e.g., arrays pushed to 0x100000 elements) followed by setSubscribedTags calls — characteristic of the heap overflow trigger. ↗
- →The vulnerability is a heap overflow (not UAF): a 4*0x100000 byte buffer is allocated, freed, then a 4*4 byte buffer is reallocated, and 0x100000 pointers are written into the 0x10-byte buffer — monitor for anomalous heap allocations in Flash player processes consistent with this pattern. ↗
- →Flag SWF files referencing flash.media.AVSegmentedSource with setSubscribedTags, setCuePointTags, or setSubscribedTagsForBackgroundManifest method calls for further analysis. ↗
- ·The exploit was developed and tested against pepflashplayer.dll version 17.0.0.134 based at 0x10000000; hardcoded offsets (e.g., sub_103255AD, offset 0x54, 0x58) are specific to this base address and version and will differ in other builds. ↗
- ·The vulnerability affects Flash Player before 13.0.0.289 and 14.x–17.x before 17.0.0.188 on Windows/OS X, and before 11.2.202.460 on Linux; Adobe AIR and AIR SDK/Compiler before 17.0.0.172 are also affected. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3g79-rhqv-wh3r: Heap-based buffer overflow in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2015-3088 [HIGH] CWE-119 GHSA-3g79-rhqv-wh3r: Heap-based buffer overflow in Adobe Flash Player before 13
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2015-3088: Heap-based buffer overflow in Adobe Flash Player before 13
osv·2015-05-13·CVSS 10.0
CVE-2015-3088 [CRITICAL] CVE-2015-3088: Heap-based buffer overflow in Adobe Flash Player before 13
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-09
vendor_redhat·2015-05-12·CVSS 10.0
CVE-2015-3088 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-09
flash-plugin: multiple code execution issues fixed in APSB15-09
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
Bugzilla
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
bugzilla·2016-05-24·CVSS 5.0
CVE-2016-3088 [MEDIUM] CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
Multiple vulnerabilities have been identified in the Apache ActiveMQ Fileserver web application. These are similar to those reported in CVE-2015-1830 and can allow attackers to replace web application files with malicious code and perform remote code execution on the system.
Mitigation:
Users are advised to use other FTP and HTTP based file servers for transferring blob messages. Fileserver web application SHOULD NOT be used in older version of the broker and it should be disabled (it has been disabled by default since 5.12.0). This can be done by removing (commenting out) the following lines from conf\jetty.xml file
External Reference:
http://activemq.apache.org/security-advisories.data/CVE-2016-3088
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-09
bugzilla·2015-05-13·CVSS 10.0
CVE-2015-3078 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-09
flash-plugin: multiple code execution issues fixed in APSB15-09
Adobe Security Bulletin APSB15-09 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-09:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-3078, CVE-2015-3089, CVE-2015-3090, CVE-2015-3093).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2015-3088).
These updates resolve validation bypass issues that could be exploited to write arbitrary data to the file system under user permissions (CVE-2015-3082, CVE-2015-3083, CVE-2015-3085).
These updates resolve an integer overflow vulnerability that could lead to c
Zscaler
Zscaler detects Flash Player Vulnerabilities | 05-21-2015
blogs_zscaler
Zscaler detects Flash Player Vulnerabilities | 05-21-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1005.htmlhttp://www.securityfocus.com/bid/74609http://www.securitytracker.com/id/1032285https://helpx.adobe.com/security/products/flash-player/apsb15-09.htmlhttps://security.gentoo.org/glsa/201505-02https://www.exploit-db.com/exploits/37844/http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1005.htmlhttp://www.securityfocus.com/bid/74609http://www.securitytracker.com/id/1032285https://helpx.adobe.com/security/products/flash-player/apsb15-09.htmlhttps://security.gentoo.org/glsa/201505-02https://www.exploit-db.com/exploits/37844/
2015-05-13
Published