CVE-2015-5130

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

References

http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00018.html

http://rhn.redhat.com/errata/RHSA-2015-1603.html

http://www.securityfocus.com/bid/76288

http://www.securitytracker.com/id/1033235

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722

https://helpx.adobe.com/security/products/flash-player/apsb15-19.html

https://security.gentoo.org/glsa/201508-01

https://www.exploit-db.com/exploits/37854/

Details

Source: MITRE

Published: 2015-08-14

Updated: 2018-01-05

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (18 total)

IDNameProductFamilySeverity
8885Google Chrome OS < 44.0.2403.155 Multiple VulnerabilitiesNessus Network MonitorMobile Devices
critical
8883Google Chrome < 44.0.2403.155 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
86089GLSA-201508-01 : Adobe Flash Player: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
8857Flash Player < 18.0.0.232 Multiple Vulnerabilities (APSB15-19)Nessus Network MonitorWeb Clients
critical
8848Adobe AIR < 18.0.0.199 Multiple Vulnerabilities (APSB15-19)Nessus Network MonitorWeb Clients
critical
85568Google Chrome < 44.0.2403.155 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
85567Google Chrome < 44.0.2403.155 Multiple VulnerabilitiesNessusWindows
critical
85435openSUSE Security Update : flash-player (openSUSE-2015-546)NessusSuSE Local Security Checks
critical
85434openSUSE Security Update : flash-player (openSUSE-2015-545)NessusSuSE Local Security Checks
critical
85378SUSE SLED12 Security Update : flash-player (SUSE-SU-2015:1374-1)NessusSuSE Local Security Checks
critical
85377SUSE SLED11 Security Update : flash-player (SUSE-SU-2015:1373-1)NessusSuSE Local Security Checks
critical
85372RHEL 5 / 6 : flash-plugin (RHSA-2015:1603)NessusRed Hat Local Security Checks
critical
85370FreeBSD : Adobe Flash Player -- critical vulnerabilities (f3778328-d288-4b39-86a4-65877331eaf7)NessusFreeBSD Local Security Checks
critical
85329MS KB3087916: Update for Vulnerabilities in Adobe Flash Player in Internet ExplorerNessusWindows
critical
85328Adobe Flash Player <= 18.0.0.209 Multiple Vulnerabilities (APSB15-19) (Mac OS X)NessusMacOS X Local Security Checks
critical
85327Adobe AIR for Mac <= 18.0.0.180 Multiple Vulnerabilities (APSB15-16)NessusMacOS X Local Security Checks
critical
85326Adobe Flash Player <= 18.0.0.209 Multiple Vulnerabilities (APSB15-19)NessusWindows
critical
85325Adobe AIR <= 18.0.0.180 Multiple Vulnerabilities (APSB15-19)NessusWindows
critical