CVE-2015-0313

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html Mailing List Third Party Advisory
http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html Exploit Third Party Advisory VDB Entry
http://secunia.com/advisories/62528 Broken Link
http://secunia.com/advisories/62777 Broken Link
http://secunia.com/advisories/62895 Broken Link
http://www.osvdb.org/117853 Broken Link
http://www.securityfocus.com/bid/72429 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1031686 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 Third Party Advisory VDB Entry
https://helpx.adobe.com/security/products/flash-player/apsa15-02.html Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html Broken Link
https://technet.microsoft.com/library/security/2755801 Patch Vendor Advisory
https://www.exploit-db.com/exploits/36579/ Exploit Third Party Advisory VDB Entry
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html Mailing List Third Party Advisory
http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html Exploit Third Party Advisory VDB Entry
http://secunia.com/advisories/62528 Broken Link
http://secunia.com/advisories/62777 Broken Link
http://secunia.com/advisories/62895 Broken Link
http://www.osvdb.org/117853 Broken Link
http://www.securityfocus.com/bid/72429 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1031686 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/100641 Third Party Advisory VDB Entry
https://helpx.adobe.com/security/products/flash-player/apsa15-02.html Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb15-04.html Broken Link
https://technet.microsoft.com/library/security/2755801 Patch Vendor Advisory
https://www.exploit-db.com/exploits/36579/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:-:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-02-02 19:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-0313

Mitre link : CVE-2015-0313

CVE.ORG link : CVE-2015-0313


JSON object : View

Products Affected

opensuse

  • opensuse
  • evergreen

microsoft

  • windows_rt
  • windows_8.1
  • windows_server_2012
  • windows_rt_8.1
  • windows_10_1507
  • edge
  • windows_8
  • internet_explorer
  • windows

adobe

  • flash_player

suse

  • linux_enterprise_desktop
  • linux_enterprise_workstation_extension

apple

  • mac_os_x

linux

  • linux_kernel
CWE
CWE-416

Use After Free