Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-4936

CWE-119Buffer Overflow7 documents7 sources
Severity
6.5MEDIUM
EPSS
41.8%
top 2.58%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 19
Latest updateMay 13

Description

Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5adobe_flash_player_29.0.0.113_and_earlier_versionsAdobe Flash Player 29.0.0.113 and earlier versions
NVDadobe/flash_player29.0.0.113
Ubuntuflashplugin-nonfree< 29.0.0.140ubuntu0.14.04.1+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rvf6-cp8q-hrxp: Adobe Flash Player versions 292022-05-13
OSV
CVE-2018-4936: Adobe Flash Player versions 292018-05-19
CVEList
CVE-2018-4936: Adobe Flash Player versions 292018-05-19

💥Exploits & PoCs

1
Exploit-DB
Adobe Flash - Overflow when Playing Sound2018-04-24

📋Vendor Advisories

1
Red Hat
flash-plugin: Information Disclosure vulnerabilities (APSB18-08)2018-04-10

💬Community

1
Bugzilla
CVE-2018-4936 CVE-2018-4933 CVE-2018-4934 flash-plugin: Information Disclosure vulnerabilities (APSB18-08)2018-04-10