Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-5122

Опубликовано: 14 июл. 2015
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 10
CVSS3: 9.8

Описание

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

РелизСтатусПримечание
devel

released

1:20150714.1-0wily1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:20150714.1-0trusty1]]
precise

released

1:20150714.1-0precise1
trusty

released

1:20150714.1-0trusty1
trusty/esm

DNE

trusty was released [1:20150714.1-0trusty1]
upstream

released

11.2.22.481
utopic

released

1:20150714.1-0utopic1
vivid

released

1:20150714.1-0vivid1

Показывать по

РелизСтатусПримечание
devel

released

11.2.202.481ubuntu2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [11.2.202.481ubuntu0.14.04.2]]
precise

released

11.2.202.481ubuntu0.12.04.2
trusty

released

11.2.202.481ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [11.2.202.481ubuntu0.14.04.2]
upstream

released

11.2.22.481
utopic

released

11.2.202.481ubuntu0.14.10.2
vivid

released

11.2.202.481ubuntu0.15.04.2

Показывать по

EPSS

Процентиль: 100%
0.9278
Критический

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
больше 10 лет назад

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

CVSS3: 9.8
nvd
больше 10 лет назад

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

CVSS3: 9.8
github
больше 3 лет назад

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

fstec
больше 10 лет назад

Уязвимость программной платформы Flash Player, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

fstec
больше 10 лет назад

Уязвимость программной платформы Flash Player, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 100%
0.9278
Критический

10 Critical

CVSS2

9.8 Critical

CVSS3