CVE-2018-4944
published 2018-05-19CVE-2018-4944: Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
8.80%
94.6th percentile
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 29.0.0.140 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w5rc-5jqm-p8hv: Adobe Flash Player versions 29
ghsa_unreviewed·2022-05-13
CVE-2018-4944 [CRITICAL] CWE-704 GHSA-w5rc-5jqm-p8hv: Adobe Flash Player versions 29
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
OSV
CVE-2018-4944: Adobe Flash Player versions 29
osv·2018-05-19·CVSS 9.8
CVE-2018-4944 [CRITICAL] CVE-2018-4944: Adobe Flash Player versions 29
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-16)
vendor_redhat·2018-05-08·CVSS 9.8
CVE-2018-4944 [CRITICAL] CWE-843 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-16)
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-16)
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
No detection rules found.
No public exploits indexed.
Tenable
Microsoft May Madness
blogs_tenable·2018-05-09
Microsoft May Madness
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft May Madness
blogs_tenable·2018-05-09·CVSS 9.8
[CRITICAL] Microsoft May Madness
Blog / Research
Subscribe
# Microsoft May Madness
Josef Weiss
May 9, 2018
4 Min Read
Patch Tuesday was anything but typical in the month of May. On May 8, Microsoft released security patches for a total of 67 vulnerabilities, addressing 21 critical vulnerabilities, 42 important and four low-severity, while Adobe addressed a critical flaw in Adobe Flash Player. This is a big push from Microsoft in securing Windows, coming right after the recent release of Windows 10, version 1803, which added several security improvements, among other feature updates.
However, what makes this update particularly important is that it addresses two zero-day vulnerabilities that are being actively exploited in the wild and a further two for which public exploits have been published.
The first critical v
Qualys
May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
## OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174 , which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008, which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16.
### Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of these is notable and requires prompt attenti
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
## Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008 , which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16 .
## Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of thes
Qualys
May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
### OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174, which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
Zscaler
Zscaler protects against 38 new vulnerabilities for Adobe Fl
blogs_zscaler
Zscaler protects against 38 new vulnerabilities for Adobe Fl
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
arxiv_fulltext·2025-08-21
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
@IEEEauthorhalign
@IEEEauthorhalign
Sabine Houy
Ume University
[email protected]
Bruno Kreyssig
Ume University
[email protected]
Timoth\'ee Riom
Ume University
[email protected]
Alexandre Bartel
Ume University
[email protected]
Patrick McDaniel
University of Wisconsin-Madison
[email protected]
## Abstract
Memory corruption vulnerabilities remain one of the most severe threats to software security. They often allow attackers to achieve arbitrary code execution by redirecting a vulnerable program's control flow.
While Control Flow Integrity (CFI) has gained traction to mitigate this exploitation path, developers are not provided with any direction on how to apply CFI to real-world software.
Bugzilla
CVE-2018-4944 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-16)
bugzilla·2018-05-08·CVSS 9.8
CVE-2018-4944 [CRITICAL] CVE-2018-4944 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-16)
CVE-2018-4944 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-16)
Adobe Security Bulletin APSB18-16 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Type Confusion -- CVE-2018-4944
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-16.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1367 https://access.redhat.com/errata/RHSA-2018:1367
http://www.securityfocus.com/bid/104101http://www.securitytracker.com/id/1040840https://access.redhat.com/errata/RHSA-2018:1367https://helpx.adobe.com/security/products/flash-player/apsb18-16.htmlhttps://security.gentoo.org/glsa/201806-02http://www.securityfocus.com/bid/104101http://www.securitytracker.com/id/1040840https://access.redhat.com/errata/RHSA-2018:1367https://helpx.adobe.com/security/products/flash-player/apsb18-16.htmlhttps://security.gentoo.org/glsa/201806-02
2018-05-19
Published