10

CVE-2015-0313

Warnung
Exploit
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version < 11.2.202.442
   Linux ≫ Linux Kernel Version -
Adobe ≫ Flash Player Version < 13.0.0.269
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version >= 14.0.0.125 < 16.0.0.305
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Opensuse ≫ Evergreen Version 11.4
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows 8 Version -
   Microsoft ≫ Windows Rt Version -
   Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Internet Explorer Version 11 Update -
   Microsoft ≫ Windows 10 1507 Version -
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Edge Version -
   Microsoft ≫ Windows 10 1507 Version -

13.04.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Adobe Flash Player Use-After-Free Vulnerability

Schwachstelle

Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

Beschreibung

The impacted product is end-of-life and should be disconnected if still in use.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 95.68% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://technet.microsoft.com/library/security/2755801
Patch
Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html
Third Party Advisory
Exploit
VDB Entry
http://secunia.com/advisories/62528
Broken Link
http://secunia.com/advisories/62777
Broken Link
http://secunia.com/advisories/62895
Broken Link
http://www.osvdb.org/117853
Broken Link
http://www.securityfocus.com/bid/72429
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1031686
Third Party Advisory
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/100641
Third Party Advisory
VDB Entry
https://helpx.adobe.com/security/products/flash-player/apsa15-02.html
Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html
Broken Link
https://www.exploit-db.com/exploits/36579/
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-0313
US Government Resource
https://github.com/cisagov/vulnrichment/issues/196
Issue Tracking