CVE-2018-5001

CWE-125Out-of-bounds Read6 documents6 sources
Severity
6.5MEDIUM
EPSS
1.0%
top 23.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateMay 14

Description

Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5adobe_flash_player_29.0.0.171_and_earlier_versionsAdobe Flash Player 29.0.0.171 and earlier versions
NVDadobe/flash_player29.0.0.171
Ubuntuflashplugin-nonfree< 30.0.0.113ubuntu0.14.04.1+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-763q-c4f2-pmv8: Adobe Flash Player versions 292022-05-14
CVEList
CVE-2018-5001: Adobe Flash Player versions 292018-07-09
OSV
CVE-2018-5001: Adobe Flash Player versions 292018-07-09

📋Vendor Advisories

1
Red Hat
flash-plugin: Information Disclosure vulnerabilities (APSB18-19)2018-06-07

💬Community

1
Bugzilla
CVE-2018-5000 CVE-2018-5001 flash-plugin: Information Disclosure vulnerabilities (APSB18-19)2018-06-07