CVE-2015-5124

CWE-119Buffer Overflow5 documents5 sources
Severity
10.0CRITICAL
EPSS
11.4%
top 6.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 14

Description

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, and CVE-2015-4431.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages6 packages

NVDadobe/flash_player13.0.0.289+21
NVDadobe/air18.0.0.144
NVDadobe/air_sdk18.0.0.144
Ubuntuflashplugin-nonfree< 11.2.202.481ubuntu0.14.04.1

🔴Vulnerability Details

3
GHSA
GHSA-94g5-gx7p-j72m: Adobe Flash Player before 132022-05-14
OSV
CVE-2015-5124: Adobe Flash Player before 132015-07-20
CVEList
CVE-2015-5124: Adobe Flash Player before 132015-07-20

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-162015-07-08
CVE-2015-5124 (CRITICAL CVSS 10) | Adobe Flash Player before 13.0.0.30 | cvebase.io