CVE-2015-3133
published 2015-07-09CVE-2015-3133: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180…
PriorityP275critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
5.31%
91.7th percentile
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 18.0.0.144 | — |
| adobe | air_sdk | <= 18.0.0.144 | — |
| adobe | air_sdk_compiler | <= 18.0.0.144 | — |
| adobe | flash_player | <= 11.2.202.468 | — |
| adobe | flash_player | <= 13.0.0.289 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
registryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL = http://127.0.0.1:[random]/[random]↗
- →KRBanker (Blackmoon) uses the KaiXin exploit kit to deliver payloads via CVE-2015-3133 (Adobe Flash) through malicious JavaScript on compromised websites or advertisements. ↗
- →KRBanker uses Process Hollowing to inject malicious code into a clean PE file from the System directory — monitor for suspicious child processes spawned from legitimate Windows system executables with anomalous network activity. ↗
- →Detect KRBanker pharming setup by monitoring for creation or modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL pointing to 127.0.0.1. ↗
- →KRBanker resolves its pharming C2 IP by querying the QZone API (users.qzone.qq.com) and parsing the 'nickname' field — monitor for unusual outbound HTTP requests to this endpoint from non-browser processes. ↗
- →KRBanker registers infected hosts to C2 via HTTP GET to /ca.php with MAC address and code page parameters — monitor for HTTP GET requests matching this URI pattern to external IPs. ↗
- ·The pharming C2 IP (23.107.204.38) is an example extracted from a QZone profile nickname field and may rotate frequently — over 200+ pharming server addresses were identified in 6 months. ↗
- ·The AutoConfigURL registry value uses random port and path components, making static string matching insufficient — pattern-based detection on 127.0.0.1 as proxy is required. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-16
vendor_redhat·2015-07-08·CVSS 10.0
CVE-2015-4431 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, and CVE-2015-3134.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-16
vendor_redhat·2015-07-08·CVSS 10.0
CVE-2015-3134 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, and CVE-2015-4431.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-16
vendor_redhat·2015-07-08·CVSS 10.0
CVE-2015-3117 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-16
vendor_redhat·2015-07-08·CVSS 10.0
CVE-2015-5124 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-16
vendor_redhat·2015-07-08·CVSS 10.0
CVE-2015-3133 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-16
vendor_redhat·2015-07-08·CVSS 10.0
CVE-2015-3130 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-16
vendor_redhat·2015-07-08·CVSS 10.0
CVE-2015-3123 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
GHSA
GHSA-fg32-r728-m423: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3123 [CRITICAL] CWE-119 GHSA-fg32-r728-m423: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
GHSA
GHSA-m63g-4c46-827h: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3134 [CRITICAL] CWE-119 GHSA-m63g-4c46-827h: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, and CVE-2015-4431.
GHSA
GHSA-3m2g-vv9f-ghpw: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3130 [CRITICAL] CWE-119 GHSA-3m2g-vv9f-ghpw: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
GHSA
GHSA-j89r-ph4h-8h2m: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3117 [CRITICAL] CWE-119 GHSA-j89r-ph4h-8h2m: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
GHSA
GHSA-4r75-m9pv-vwvf: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-3133 [CRITICAL] CWE-119 GHSA-4r75-m9pv-vwvf: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.
GHSA
GHSA-pr5m-pgx3-j358: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-4431 [CRITICAL] CWE-119 GHSA-pr5m-pgx3-j358: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, and CVE-2015-3134.
GHSA
GHSA-94g5-gx7p-j72m: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-5124 [CRITICAL] CWE-119 GHSA-94g5-gx7p-j72m: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
OSV
CVE-2015-5124: Adobe Flash Player before 13
osv·2015-07-20·CVSS 10.0
CVE-2015-5124 [CRITICAL] CVE-2015-5124: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
OSV
CVE-2015-3117: Adobe Flash Player before 13
osv·2015-07-09·CVSS 10.0
CVE-2015-3117 [CRITICAL] CVE-2015-3117: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
OSV
CVE-2015-3133: Adobe Flash Player before 13
osv·2015-07-09·CVSS 10.0
CVE-2015-3133 [CRITICAL] CVE-2015-3133: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.
OSV
CVE-2015-3123: Adobe Flash Player before 13
osv·2015-07-09·CVSS 10.0
CVE-2015-3123 [CRITICAL] CVE-2015-3123: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
OSV
CVE-2015-3130: Adobe Flash Player before 13
osv·2015-07-09·CVSS 10.0
CVE-2015-3130 [CRITICAL] CVE-2015-3130: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.
OSV
CVE-2015-3134: Adobe Flash Player before 13
osv·2015-07-09·CVSS 10.0
CVE-2015-3134 [CRITICAL] CVE-2015-3134: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, and CVE-2015-4431.
OSV
CVE-2015-4431: Adobe Flash Player before 13
osv·2015-07-09·CVSS 10.0
CVE-2015-4431 [CRITICAL] CVE-2015-4431: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, and CVE-2015-3134.
VulnCheck
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2015·CVSS 10.0
CVE-2015-3133 [CRITICAL] Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation Ref
No detection rules found.
No public exploits indexed.
Unit42
KRBanker Targets South Korea Through Adware and Exploit Kits
blogs_unit42·2016-05-09·CVSS 9.3
[CRITICAL] KRBanker Targets South Korea Through Adware and Exploit Kits
Online banking services have been a prime target of cyber criminals for many years and attacks continue to grow. Targeting online banking users and stealing their credentials has yielded huge profits for the criminals behind these campaigns. Unit 42 has been tracking "KRBanker" AKA 'Blackmoon', since late last year. This campaign specifically targets banks of the Republic of Korea. On April 23, researchers at Fortinet published a blog describing the functionalities of the recent 'Blackmoon' campaign. Our objective in this blog is to share additional details on the distribution of the KRBanker or Blackmoon malware campaign and indicators of KRBanker samples.
Early variants of this campaign started surfacing in late September 2015. Though the number of KRBanker infection attempts was relati
Unit42
KRBanker Targets South Korea Through Adware and Exploit Kits
blogs_unit42·2016-05-09·CVSS 9.3
[CRITICAL] KRBanker Targets South Korea Through Adware and Exploit Kits
Threat Research Center
Threat Research
Malware
## KRBanker Targets South Korea Through Adware and Exploit Kits
Vicky Ray
Kaoru Hayashi
Published: May 9, 2016
Cybercrime
Malware
Threat Research
Adware
Banking Trojan
Blackmoon
ExploitKit
KRBanker
Pharming
Republic of Korea
Online banking services have been a prime target of cyber criminals for many years and attacks continue to grow. Targeting online banking users and stealing their credentials has yielded huge profits for the criminals behind these campaigns. Unit 42 has been tracking "KRBanker" AKA 'Blackmoon', since late last year. This campaign specifically targets banks of the Republic of Korea. On April 23, researchers at Fortinet published a blog describing the functionalities of the recent 'Blackmoon' campaign. Our
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-16
bugzilla·2015-07-08·CVSS 10.0
CVE-2015-3135 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Security Bulletin APSB15-16 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-16:
These updates resolve heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-3135, CVE-2015-4432, CVE-2015-5118).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, CVE-2015-4431).
These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2015-3119, CVE-2015-3120, CVE-2015-3121, CVE-2015-3122, CVE-2015-4433).
These updates resolve use-aft
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1214.htmlhttp://www.securityfocus.com/bid/75591http://www.securitytracker.com/id/1032810https://helpx.adobe.com/security/products/flash-player/apsb15-16.htmlhttps://security.gentoo.org/glsa/201507-13http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1214.htmlhttp://www.securityfocus.com/bid/75591http://www.securitytracker.com/id/1032810https://helpx.adobe.com/security/products/flash-player/apsb15-16.htmlhttps://security.gentoo.org/glsa/201507-13
2015-07-09
Published
Exploited in the wild