CVE-2015-3113
Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
Desbordamiento de buffer basado en memoria dinámica en Adobe Flash Player anterior a 13.0.0.296 y 14.x hasta 18.x anterior a 18.0.0.194 en Windows y OS X y anterior a 11.2.202.468 en Linux permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados, tal y como fue utilizado activamente en junio del 2015.
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-04-09 CVE Reserved
- 2015-06-23 CVE Published
- 2015-07-08 First Exploit
- 2022-04-13 Exploited in Wild
- 2022-05-04 KEV Due Date
- 2024-07-03 EPSS Updated
- 2024-08-06 CVE Updated
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (19)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/37536 | 2015-07-08 |
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/flash-player/apsb15-14.html | 2015-06-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | < 13.0.0.296 Search vendor "Adobe" for product "Flash Player" and version " < 13.0.0.296" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | < 13.0.0.296 Search vendor "Adobe" for product "Flash Player" and version " < 13.0.0.296" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 14.0.0.125 < 18.0.0.194 Search vendor "Adobe" for product "Flash Player" and version " >= 14.0.0.125 < 18.0.0.194" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 14.0.0.125 < 18.0.0.194 Search vendor "Adobe" for product "Flash Player" and version " >= 14.0.0.125 < 18.0.0.194" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | < 11.2.202.468 Search vendor "Adobe" for product "Flash Player" and version " < 11.2.202.468" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Opensuse Search vendor "Opensuse" | Evergreen Search vendor "Opensuse" for product "Evergreen" | 11.4 Search vendor "Opensuse" for product "Evergreen" and version "11.4" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.1 Search vendor "Opensuse" for product "Opensuse" and version "13.1" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.2 Search vendor "Opensuse" for product "Opensuse" and version "13.2" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Desktop Search vendor "Suse" for product "Linux Enterprise Desktop" | 12 Search vendor "Suse" for product "Linux Enterprise Desktop" and version "12" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Workstation Extension Search vendor "Suse" for product "Linux Enterprise Workstation Extension" | 12 Search vendor "Suse" for product "Linux Enterprise Workstation Extension" and version "12" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Insight Orchestration Search vendor "Hp" for product "Insight Orchestration" | < 7.5.0 Search vendor "Hp" for product "Insight Orchestration" and version " < 7.5.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | System Management Homepage Search vendor "Hp" for product "System Management Homepage" | < 7.5.0 Search vendor "Hp" for product "System Management Homepage" and version " < 7.5.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Systems Insight Manager Search vendor "Hp" for product "Systems Insight Manager" | < 7.5 Search vendor "Hp" for product "Systems Insight Manager" and version " < 7.5" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Version Control Agent Search vendor "Hp" for product "Version Control Agent" | < 7.5.0 Search vendor "Hp" for product "Version Control Agent" and version " < 7.5.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Version Control Repository Manager Search vendor "Hp" for product "Version Control Repository Manager" | < 7.5.0 Search vendor "Hp" for product "Version Control Repository Manager" and version " < 7.5.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Version Control Repository Manager Search vendor "Hp" for product "Version Control Repository Manager" | 7.6 Search vendor "Hp" for product "Version Control Repository Manager" and version "7.6" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Virtual Connect Enterprise Manager Search vendor "Hp" for product "Virtual Connect Enterprise Manager" | < 7.5.0 Search vendor "Hp" for product "Virtual Connect Enterprise Manager" and version " < 7.5.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 6.6 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "6.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
|