Skip to main content

CVE detail

CVE-2015-3113

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

CVSS 9.8 · CriticalBuzz score 70.4KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 70.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 29.4 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
29.4
18 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
18 source links · newest first
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • A total of 295 incidents involving critical infrastructure in the U.S.

    newswww.securityweek.comJan 20, 2016, 12:08 PM
  • A June 23 FireEye blog post titled “Operation Clandestine Wolf” discussed a cyber espionage group, known as APT3, that had been exploiting a zero-day vulnerability in Adobe Flash. Unit 42 also tracks the APT3 group using the name UPS, which is an intrusion set with Chinese origins that is known for having early access to

    vendorunit42.paloaltonetworks.comJul 27, 2015, 10:50 AM
  • On July 8, 2015, Unit 42 used the AutoFocus Threat Intelligence service to locate and investigate activity consistent with a spear-phishing attack targeting the US Government. The attack exploited an Adobe Flash vulnerability that stems from the zero-day vulnerabilities exposed from this month’s Hacking Team data breach. The spear-phishing attack used a link to a

    vendorunit42.paloaltonetworks.comJul 10, 2015, 8:36 AM
  • Here’s an overview of some of last week’s most interesting news and articles:5 ways to stop the Internet of Things from becoming the Internet of ThievesThis is the Internet universalized, embedded more deeply into every aspect of our lives, using volumes of data to automate what we humans don’t always get right. But it won’t be possible to take human nature completely out of the mix. (IN)SECURE Magazine issue 46 released(IN)SECURE Magazine is a free … More →

    newswww.helpnetsecurity.comJul 6, 2015, 12:23 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box. US Healthcare companies are the most targeted by Stegoloader Popular travel websites warn Customers of Phishing scam Ransomware slinging exploit kit targets Flash remote code execution Experts found Government […]

    newssecurityaffairs.comJul 5, 2015, 11:47 AM
  • Security researcher discovered a strain of the Kovter trojan that has been updating Flash Player and Internet Explorer to prevent further infections. The French security expert Kafeine have discovered a new strain of the Kovter malware noticing that the instance of the malicious code he was analyzing was attempting to download the latest version of the Flash […]

    newssecurityaffairs.comJul 4, 2015, 5:13 AM
  • The ad fraud Trojan known as Kovter has been updating Adobe Flash Player and Microsoft Internet Explorer on infected systems, most likely in an effort to keep other malware out. The French security researcher known as Kafeine discovered this new Kovter trick when he noticed that some of his virtual machines were attempting to download the latest version of Flash Player.

    newswww.securityweek.comJul 3, 2015, 11:47 AM
  • Just four days after Adobe Systems patched a vulnerability in Flash Player, the exploit was adopted by cybercriminals for use in large-scale attacks. This highlights the increasingly small time frame users have to deploy patches. On Saturday, a malware researcher known online as Kafeine spotted a drive-by download attack done with the Magnitude exploit kit […]

    newswww.csoonline.comJun 29, 2015, 5:48 PM
  • The French researcher Kafeine confirmed that the author of the Magnitude exploit kit have added the code to exploit the Adobe CVE-2015-3113 flaw. Cyber criminals have added the recently the recently discovered CVE-2015-3113 to the popular Magnitude exploit kit. Last week, Adobe released a security update for the critical Adobe Flash Player vulnerability CVE-2015-3113 that is […]

    newssecurityaffairs.comJun 29, 2015, 9:44 AM
  • An exploit for a Flash Player vulnerability patched by Adobe last week with the release of version 18.0.0.194 has been integrated into the Magnitude exploit kit.

    newswww.securityweek.comJun 29, 2015, 9:02 AM
  • “It didn’t take long for exploit kit authors to incorporate an exploit for the recently discovered zero-day Adobe Flash vulnerability (CVE-2015-3113) into their malicious wares. According to malware researcher Kafeine, the Magnitude exploit kit has been successfully exploiting Flash 18.0.0.160 on IE11 in Windows 7 since Saturday, only four days after the flaw was patched by Adobe with an out-of-band update. Magnitude EK is currently dropping Cryptowall ransomware onto unsuspecting users. Magnitude EK authors have … More →

    newswww.helpnetsecurity.comJun 29, 2015, 4:00 AM
  • Recent Flash Player 0-day Exploit Goes MainstreamMalwarebytes Labs

    Security firm FireEye released a report on June 23 about targeted attacks leveraging a Flash Player zero-day vulnerability (CVE-2015-3113) in Adobe Flash Player…

    newswww.malwarebytes.comJun 27, 2015, 5:00 PM
  • Researchers at Trend Micro say the zero-day vulnerability patched Tuesday by Adobe Systems has a similar underlying cause as an older flaw .

    newswww.securityweek.comJun 24, 2015, 9:03 PM
  • Adobe has released a security update for the critical Adobe Flash Player vulnerability CVE-2015-3113 that is being actively exploited in the wild. Security experts at FireEye discovered a critical heap buffer overflow vulnerability, coded CVE-2015-3113, that affects Adobe systems. FireEye discovered that the Adobe flaw is being exploited in the wild by the hacking crew […]

    newssecurityaffairs.comJun 23, 2015, 9:45 PM
  • Adobe Systems released an emergency update today to address a security vulnerability in Adobe Flash Player that is being exploited in a large-scale phishing campaign.

    newswww.securityweek.comJun 23, 2015, 8:20 PM
  • Adobe has released an emergency patch for its notoriously buggy Flash Player software because attackers are actively exploiting a critical vulnerability that can lead to total system compromise.“Adobe is aware of reports that CVE-2015-3113 is being actively exploited in the wild via limited, targeted attacks. Systems running Internet Explorer for Windows 7 and below, as well as Firefox on Windows XP, are known targets,” the company shared in a security bulletin published on Tuesday.The vulnerability … More →

    newswww.helpnetsecurity.comJun 23, 2015, 9:39 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence