CVE detail
CVE-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
21 source links · newest first
It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.
newswww.securityweek.comJan 20, 2017, 4:16 PMAs if you need more reasons to hate Adobe Flash, it’s unsurprisingly a favorite among cyber criminals to roll into exploit kits. The most popular exploit kit right now is Angler, which has been around since 2013, but it is still “regularly tied to malware including Cryptolocker.” According to a new report by Recorded Future, […]
newswww.csoonline.comNov 9, 2015, 5:09 PMJust days after the developers of the Angler exploit kit started leveraging a recently patched Flash Player vulnerability to distribute malware, an exploit for the same security bug was also added to the Magnitude, Neutrino and Nuclear Pack exploit kits.
newswww.securityweek.comJun 2, 2015, 11:34 AMWhat follows is a detailed analysis of the root cause of a vulnerability we call CVE-2015-X, as well as a step-by-step explanation of how to trigger it. For more on Flash vulnerabilities, we also invite you to read "The Latest UAF Vulnerabilities in Exploit Kits," published May 28 by Tao Yan. Not too long ago we
vendorunit42.paloaltonetworks.comJun 1, 2015, 8:20 PMIntroduction Recently, several popular exploit kits, including Angler, Flash EK, SweetOrange, Fiesta andNeutrino[1], have included several use-after-free (UAF) vulnerabilities in Adobe Flash to exploit victims’ browsers. Previously, these exploit kits typically used out-of-bounds access (OBA) vulnerabilities in Adobe Flash, as these types of vulnerabilities can be exploited universally and stably [2], and require less effort
vendorunit42.paloaltonetworks.comMay 28, 2015, 1:00 PM- Tech Brief: An inside view of a zero-day campaignMalwarebytes Labs
OverviewDiscovering a new vulnerability in a popular piece of software is the Holy Grail for cybercriminals. The period between this vulnerability…
newswww.malwarebytes.comApr 20, 2015, 5:00 PM Over a hundred forum websites have been compromised and injected with code that redirects users to sites hosting the Fiesta exploit kit, Cyphort researchers have found. These are not highly popular forums, but gather a respectable number of users who like to discuss DIY projects, animals, wrestling, scuba diving, news regarding PS3, and so on. They are powered by either vBulletin or by IP Board online forum software, new vulnerabilities for which are often found … More →
newswww.helpnetsecurity.comApr 10, 2015, 12:12 AM- Hanjuan EK’s ‘March Madness’ malvertising campaignMalwarebytes Labs
Update: The ad network, Engage:BDR terminated the malvertising account quickly after notification, on Monday at 10:32AM. We can confirm that this…
newswww.malwarebytes.comMar 23, 2015, 5:00 PM - Top Adult Site RedTube Compromised, Redirects to MalwareMalwarebytes Labs
DISCLAIMER: THIS POST INCLUDES SOME LANGUAGE AND TOPICS THAT MIGHT NOT BE SUITABLE FOR ALL READERS, PLEASE BE ADVISED AND PROCEED…
newswww.malwarebytes.comFeb 17, 2015, 5:00 PM Here’s an overview of some of last week’s most interesting news and articles: Overcoming the daily challenges of a security team The institutionalization of domestic security and incident-response into a distinct profession have formed three major challenges for large enterprises. Security outlook: Technologies and key trends Anonymous threats and lone wolf attacks, increasing fears on cyber security and concerns over immigration will generate significant debate over foreign policy and how to mitigate the security risk … More →
newswww.helpnetsecurity.comFeb 9, 2015, 12:01 AMAdobe has released Flash Player security updates that address a total of 18 vulnerabilities, most of which could be exploited for arbitrary code execution.
newswww.securityweek.comFeb 6, 2015, 11:13 AM- Fessleak malvertising campaign used to serve ransomwareSecurity Affairs
Invincea has been monitoring the Fessleak campaign in which hackers leveraged Adobe Flash Player exploits and file-less infections to serve ransomware. Security experts from Invincea are investigating on a new Ransomware campaign originated in Russia that presented many interesting characteristics. The researchers discovered that the attacks started by using file-less infections then moved to the […]
newssecurityaffairs.comFeb 6, 2015, 7:29 AM Researchers at Invincea have been monitoring a malvertising campaign in which malicious actors leveraged Adobe Flash Player exploits and file-less infections to deliver ransomware. The campaign, dubbed “ Fessleak ” based on the email address used to register the domains involved in the attack, appears to be the work of Russian cybercriminals.
newswww.securityweek.comFeb 5, 2015, 1:45 PM- Adobe patches latest Flash Player zero-dayHelp Net Security
Adobe has released Flash Player 16.0.0.305, a new version that fixes the latest zero-day flaw (CVE-2015-0313) that is currently exploited in mass malvertising campaigns. An exploit for the flaw has been recently added to the Hanjuan exploit kit, and malicious ads shown on a number of high-profile sites redirect users to sites hosting it. While the existence of the flaw was made public only this week, cyber crooks exploited it as far back as December … More →
newswww.helpnetsecurity.comFeb 5, 2015, 9:24 AM Adobe Systems has made a patch available for a zero-day vulnerability in Flash Player that came under attack in recent days.
newswww.securityweek.comFeb 5, 2015, 12:12 AMAttackers who have slipped malicious advertisements onto major websites over the last month have potentially compromised large numbers of computers. Several security vendors have documented attacks involving malicious advertisements, which automatically redirect victims to other websites or pages that silently attack their computer and install malware. “We certainly see malvertising on the rise,” said Nick […]
newswww.csoonline.comFeb 4, 2015, 12:26 PMIt has been a tough beginning of the year for Adobe and a dangerous one for Adobe Flash Player users. The recently discovered zero-day vulnerability (CVE-2015-0313) affecting the last existing version of the software is being actively exploited in the wild via the Hanjuan exploit kit. According to Malwarebytes researchers, this flaw has been exploited as far back as December 9, 2014, and users are targeted via malicious ads shown on a number of high-profile … More →
newswww.helpnetsecurity.comFeb 4, 2015, 6:11 AM- A third Flash Zero-Day is being exploited in the wildSecurity Affairs
A third critical zero-day vulnerability affects Adobe Flash Player 16.0.0.296 and earlier versions for Windows, Linux and Mac. It is the third time in a few weeks that the security of Adobe users is menaced by a zero-day in Flash that affects Windows, Linux and OS X systems. The company is already working to provide a patch […]
newssecurityaffairs.comFeb 2, 2015, 9:38 PM Adobe Systems plans to release a patch this week for a zero-day vulnerability caught being exploited in malvertising attacks.
newswww.securityweek.comFeb 2, 2015, 5:29 PM- HanJuan EK fires third Flash Player 0dayMalwarebytes Labs
A new Adobe Flash zero-day, the third one this year so far, has been found in the wild via drive-by download…
newswww.malwarebytes.comFeb 2, 2015, 5:00 PM - New Flash Player 0-day exploited in malvertising attacksHelp Net Security
A new Adobe Flash Player zero-day flaw is being actively exploited in the wild via the Angler exploit kit, Trend Micro threat analyst Peter Pi has warned. The flaw (CVE-2015-0313) affects Adobe Flash Player 16.0.0.296 and earlier versions for Windows and Macintosh, and is currently being aimes at running Internet Explorer and Firefox on Windows 8.1 and below. The active attacks have been first spotted by Trend Micro researchers. “According to our data, visitors of … More →
newswww.helpnetsecurity.comFeb 2, 2015, 12:10 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2015-0311CVSS 9.8 · Critical
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote…
KEV listed29 mentions - CVE-2015-5122CVSS 9.8 · Critical
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through…
- CVE-2015-5119CVSS 9.8 · Critical
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows…
- CVE-2016-4156CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4148CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4147CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…