CVE-2015-0313

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html Mailing List Third Party Advisory
http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html Exploit Third Party Advisory VDB Entry
http://secunia.com/advisories/62528 Broken Link
http://secunia.com/advisories/62777 Broken Link
http://secunia.com/advisories/62895 Broken Link
http://www.osvdb.org/117853 Broken Link
http://www.securityfocus.com/bid/72429 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1031686 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 Third Party Advisory VDB Entry
https://helpx.adobe.com/security/products/flash-player/apsa15-02.html Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html Broken Link
https://technet.microsoft.com/library/security/2755801 Patch Vendor Advisory
https://www.exploit-db.com/exploits/36579/ Exploit Third Party Advisory VDB Entry
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html Mailing List Third Party Advisory
https://www.exploit-db.com/exploits/36579/ Exploit Third Party Advisory VDB Entry
https://technet.microsoft.com/library/security/2755801 Patch Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html Broken Link
https://helpx.adobe.com/security/products/flash-player/apsa15-02.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1031686 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/72429 Broken Link Third Party Advisory VDB Entry
http://www.osvdb.org/117853 Broken Link
http://secunia.com/advisories/62895 Broken Link
http://secunia.com/advisories/62777 Broken Link
http://secunia.com/advisories/62528 Broken Link
http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html Exploit Third Party Advisory VDB Entry
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:-:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*

History

20 Dec 2024, 15:29

Type Values Removed Values Added
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html - Mailing List, Third Party Advisory
References (MISC) http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html - Exploit, Third Party Advisory, VDB Entry
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html - Mailing List, Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/62528 - Broken Link () http://secunia.com/advisories/62528 - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html - Mailing List, Third Party Advisory
References (CONFIRM) https://helpx.adobe.com/security/products/flash-player/apsa15-02.html - Vendor Advisory () https://helpx.adobe.com/security/products/flash-player/apsa15-02.html - Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 - Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/62895 - Broken Link () http://secunia.com/advisories/62895 - Broken Link
References (SECUNIA) http://secunia.com/advisories/62777 - Broken Link () http://secunia.com/advisories/62777 - Broken Link
References (BID) http://www.securityfocus.com/bid/72429 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/72429 - Broken Link, Third Party Advisory, VDB Entry
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html - Mailing List, Third Party Advisory
References (OSVDB) http://www.osvdb.org/117853 - Broken Link () http://www.osvdb.org/117853 - Broken Link
References (CONFIRM) https://helpx.adobe.com/security/products/flash-player/apsb15-04.html - Broken Link () https://helpx.adobe.com/security/products/flash-player/apsb15-04.html - Broken Link
References (SECTRACK) http://www.securitytracker.com/id/1031686 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1031686 - Broken Link, Third Party Advisory, VDB Entry
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/36579/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/36579/ - Exploit, Third Party Advisory, VDB Entry
References (CONFIRM) https://technet.microsoft.com/library/security/2755801 - Patch, Vendor Advisory () https://technet.microsoft.com/library/security/2755801 - Patch, Vendor Advisory

02 Jul 2024, 17:41

Type Values Removed Values Added
CWE NVD-CWE-noinfo CWE-416
CVSS v2 : 10.0
v3 : unknown
v2 : 10.0
v3 : 9.8
First Time Opensuse opensuse
Suse linux Enterprise Desktop
Microsoft windows 10 1507
Microsoft windows 8.1
Microsoft windows 8
Suse linux Enterprise Workstation Extension
Opensuse
Microsoft windows Server 2012
Microsoft internet Explorer
Opensuse evergreen
Microsoft windows Rt
Microsoft windows Rt 8.1
Suse
Microsoft edge
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html - Mailing List, Third Party Advisory
References (CONFIRM) https://helpx.adobe.com/security/products/flash-player/apsb15-04.html - (CONFIRM) https://helpx.adobe.com/security/products/flash-player/apsb15-04.html - Broken Link
References (SECUNIA) http://secunia.com/advisories/62895 - (SECUNIA) http://secunia.com/advisories/62895 - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html - Mailing List, Third Party Advisory
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/36579/ - (EXPLOIT-DB) https://www.exploit-db.com/exploits/36579/ - Exploit, Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/62528 - (SECUNIA) http://secunia.com/advisories/62528 - Broken Link
References (SECTRACK) http://www.securitytracker.com/id/1031686 - (SECTRACK) http://www.securitytracker.com/id/1031686 - Broken Link, Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/62777 - (SECUNIA) http://secunia.com/advisories/62777 - Broken Link
References (MISC) http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html - (MISC) http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html - Exploit, Third Party Advisory, VDB Entry
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html - Mailing List, Third Party Advisory
References (BID) http://www.securityfocus.com/bid/72429 - (BID) http://www.securityfocus.com/bid/72429 - Broken Link, Third Party Advisory, VDB Entry
References (CONFIRM) https://technet.microsoft.com/library/security/2755801 - (CONFIRM) https://technet.microsoft.com/library/security/2755801 - Patch, Vendor Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html - Mailing List, Third Party Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 - Third Party Advisory, VDB Entry
References (OSVDB) http://www.osvdb.org/117853 - (OSVDB) http://www.osvdb.org/117853 - Broken Link
CPE cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:-:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*

Information

Published : 2015-02-02 19:59

Updated : 2025-02-14 15:59


NVD link : CVE-2015-0313

Mitre link : CVE-2015-0313


JSON object : View

Products Affected

microsoft

  • windows_8.1
  • windows_10_1507
  • windows_8
  • internet_explorer
  • edge
  • windows_server_2012
  • windows_rt_8.1
  • windows_rt
  • windows

suse

  • linux_enterprise_workstation_extension
  • linux_enterprise_desktop

apple

  • mac_os_x

adobe

  • flash_player

opensuse

  • opensuse
  • evergreen

linux

  • linux_kernel
CWE
CWE-416

Use After Free