CVE-2015-3113

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

References

http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00020.html

http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00025.html

http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00002.html

http://marc.info/?l=bugtraq&m=144050155601375&w=2

http://rhn.redhat.com/errata/RHSA-2015-1184.html

http://www.securityfocus.com/bid/75371

http://www.securitytracker.com/id/1032696

https://bugzilla.redhat.com/show_bug.cgi?id=1235036

https://bugzilla.suse.com/show_bug.cgi?id=935701

https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952467

https://helpx.adobe.com/security/products/flash-player/apsb15-14.html

https://security.gentoo.org/glsa/201507-13

https://www.suse.com/security/cve/CVE-2015-3113.html

Details

Source: MITRE

Published: 2015-06-23

Updated: 2017-11-08

Type: CWE-119

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
86083GLSA-201507-13 : Adobe Flash Player: Multiple vulnerabilities (Underminer)NessusGentoo Local Security Checks
critical
8820Flash Player < 13.0.0.296 / 18.0.0.194 RCE (APSB15-14)Nessus Network MonitorWeb Clients
high
84424SUSE SLED11 Security Update : flash-player (SUSE-SU-2015:1137-1)NessusSuSE Local Security Checks
critical
84416openSUSE Security Update : Adobe Flash Player (openSUSE-2015-450)NessusSuSE Local Security Checks
critical
84397SUSE SLED12 Security Update : flash-player (SUSE-SU-2015:1136-1)NessusSuSE Local Security Checks
critical
84391RHEL 5 / 6 : flash-plugin (RHSA-2015:1184)NessusRed Hat Local Security Checks
critical
84383FreeBSD : Adobe Flash Player -- critical vulnerabilities (d02f6b01-1a3f-11e5-8bd6-c485083ca99c)NessusFreeBSD Local Security Checks
critical
84367MS KB3074219: Update for Vulnerabilities in Adobe Flash Player in Internet ExplorerNessusWindows
critical
84366Adobe Flash Player <= 18.0.0.161 RCE (APSB15-14) (Mac OS X)NessusMacOS X Local Security Checks
critical
84365Adobe Flash Player <= 18.0.0.161 RCE (APSB15-14)NessusWindows
critical