// For flags

CVE-2015-5125

HP Security Bulletin HPSBMU03691 1

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via unknown vectors.

Vulnerabilidad en Adobe Flash Player en versiones anteriores a 18.0.0.233 en Windows y OS X y versiones anteriores a 11.2.202.508 en Linux, en Adobe AIR en versiones anteriores a 18.0.0.199, Adobe AIR SDK en versiones anteriores a 18.0.0.199 y Adobe AIR SDK & Compiler en versiones anteriores a 18.0.0.199, permite a atacantes provocar una denegación de servicio (corrupción de longitud de vectores) o posiblemente tener otro impacto no especificado a través de vectores desconocidos.

Flash version 18.0.0.209 contains new mitigations to defend against corruptions of Vector.(and other) lengths. One of these mitigations, at Vector access time, compares the Vector's in-memory length with a representation of the same length XOR'ed with a secret cookie. The bypass comes about because the secret cookie value is stored inside a structure, and a pointer to that structure is stored alongside the Vector length.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-06-26 CVE Reserved
  • 2015-08-14 CVE Published
  • 2015-08-21 First Exploit
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
<= 18.0.0.209
Search vendor "Adobe" for product "Flash Player" and version " <= 18.0.0.209"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
--
Safe
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
<= 18.0.0.209
Search vendor "Adobe" for product "Flash Player" and version " <= 18.0.0.209"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
<= 11.2.202.491
Search vendor "Adobe" for product "Flash Player" and version " <= 11.2.202.491"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Adobe
Search vendor "Adobe"
Air
Search vendor "Adobe" for product "Air"
<= 18.0.0.180
Search vendor "Adobe" for product "Air" and version " <= 18.0.0.180"
-
Affected
Adobe
Search vendor "Adobe"
Air Sdk
Search vendor "Adobe" for product "Air Sdk"
<= 18.0.0.180
Search vendor "Adobe" for product "Air Sdk" and version " <= 18.0.0.180"
-
Affected
Adobe
Search vendor "Adobe"
Air Sdk \& Compiler
Search vendor "Adobe" for product "Air Sdk \& Compiler"
<= 18.0.0.180
Search vendor "Adobe" for product "Air Sdk \& Compiler" and version " <= 18.0.0.180"
-
Affected
Opensuse
Search vendor "Opensuse"
Evergreen
Search vendor "Opensuse" for product "Evergreen"
11.4
Search vendor "Opensuse" for product "Evergreen" and version "11.4"
-
Affected