CVE detail
CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
49 source links · newest first
- The evolutions of APT28 attacksSecurity Affairs
Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]
newssecurityaffairs.comDec 5, 2019, 6:41 AM Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
vendorunit42.paloaltonetworks.comDec 27, 2018, 2:00 PMNew Underminer exploit kit delivers a bootkit that infects the system’s boot sectors as well as a cryptocurrency miner dubbed Hidden Mellifera. Malware researchers from Trend Micro have spotted a new exploit kit, tracked as Underminer exploit kit, delivering a bootkit that infects the system’s boot sectors as well as a cryptocurrency miner dubbed Hidden Mellifera. “We […]
newssecurityaffairs.comJul 29, 2018, 8:54 AMDuring our web crawls we sometimes come across bizarre findings or patterns we haven’t seen before. This was the case with…
newswww.malwarebytes.comFeb 21, 2018, 5:00 PMSecurity researchers from Kaspersky Labs spotted the BlackOasis APT group exploiting a new zero-day RCE vulnerability in Adobe Flash. Security researchers from Kaspersky Labs have discovered a new zero-day remote code execution vulnerability in Adobe Flash, tracked as CVE-2017-11292, which was being actively exploited by hackers in the wild to deliver the surveillance software FinSpy. Hackers belonging to the […]
newssecurityaffairs.comOct 17, 2017, 7:05 AMA new exploit kit (EK) has emerged recently on underground forums, where a malware developer is advertising it starting at just $80.
newswww.securityweek.comAug 15, 2017, 12:46 PM- The Disdain exploit kit appears in the threat landscapeSecurity Affairs
The Disdain exploit kit is available for rent on a daily, weekly, or monthly basis for prices of $80, $500, and $1,400 respectively. The security researcher David Montenegro discovered a new exploit kit dubbed Disdain that is offered for rent on underground hacking forums by a malware developer using the pseudonym of Cehceny. https://twitter.com/CryptoInsane/status/895151680861253632 The Disdain exploit […]
newssecurityaffairs.comAug 15, 2017, 7:48 AM - 2017-6-26 Global Cyber Attack ReportsCheck Point Research
TOP ATTACKS AND BREACHES Honda, the Japanese motor conglomerate, has halted its car production in one of its domestic car plants, after finding WannaCry ransomware in its network. The affected plant produces approximately 1,000 vehicles a day. It is unknown how and when Honda’s network got infected. In a related topic, WannaCry has hit 55 […]
vendorresearch.checkpoint.comJun 26, 2017, 9:36 PM It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.
newswww.securityweek.comJan 20, 2017, 4:16 PM- New Terror Exploit Kit EmergesSecurityWeek
After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.
newswww.securityweek.comJan 10, 2017, 4:59 PM - Exploit kits: Fall 2016 reviewMalwarebytes Labs
There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…
newswww.malwarebytes.comNov 8, 2016, 5:00 PM - Sundown Exploit Kit Outsources Coding WorkSecurityWeek
Sundown, a relatively new exploit kit (EK), is outsourcing panel and Domain Generation Algorithm (DGA) coding work and stealing exploits in an attempt to improve its presence on the EK scene.
newswww.securityweek.comSep 5, 2016, 1:46 PM This is the second part of a two-part blog post for understanding Angler exploit kit (EK). The first part covered EKs in general. This blog focuses on the Angler EK. Angler is currently one of the most advanced, effective, and popular exploit kits in the cyber criminal market. It generally uses the most recent exploits
vendorunit42.paloaltonetworks.comJun 7, 2016, 8:00 PM- Wekby APT group leverages DNS requests for C2 communicationsSecurity Affairs
PaloAlto Networks has spotted a new campaign conducted by the Wekby APT that leverages on a malware that uses DNS requests for C2 communications. Security experts at Palo Alto Networks have spotted a China-linked APT group that has been using a strain of malware that leverages DNS requests for command and control (C&C) communications. The group […]
newssecurityaffairs.comMay 28, 2016, 7:20 AM The Angler exploit kit went on vacation during the first two weeks of the year, but the Russia-hosted RIG exploit kit was there to ensure that there would be no respite for users from malvertising and malicious drive-by downloads, according to a new report. Researchers at Cisco’s Talos Security Intelligence and Research Group traced RIG […]
newswww.csoonline.comJan 12, 2016, 3:20 PM- Experts warn Neutrino and RIG exploit kit activity spikeSecurity Affairs
Security experts at Heimdal Security are warning a spike in cyber attacks leveraging the popular Neutrino and RIG exploit kit. Cyber criminals always exploit new opportunities and users’ bad habits, now crooks behind the recent campaigns relying on Neutrino and RIG exploit kits are ramping up attacks against users that haven’s patched their Adobe Flash software. “It […]
newssecurityaffairs.comJan 12, 2016, 9:35 AM - Cisco Targets RIG Exploit KitSecurityWeek
While investigating activity associated with the RIG exploit kit, researchers at Cisco managed to cause some damage to an operation, but an uncooperative service provider prevented them from completely shutting it down.
newswww.securityweek.comJan 8, 2016, 2:06 PM - Exploit Kits Mutate, Increase Activity: ReportSecurityWeek
Security researchers have observed an increase in exploit kit (EK) activity in the beginning of this year, coupled with a series of mutations, which include spreading more malware, Heimdal Security reports.
newswww.securityweek.comJan 6, 2016, 6:21 PM - Customers of Japanese banks targeted by the Brolux TrojanSecurity Affairs
Researchers at ESET have spotted a new strain of banking Trojan dubbed Brolux that is targeting online banking users in Japan. Once again customers of the Japanese banks have been targeted by a malware, after the recent campaigns based on Shifu, Tsukuba, and Neverquest, now its time for a new threat. According to the security firm ESET […]
newssecurityaffairs.comOct 15, 2015, 8:36 PM - Banking Trojan “Brolux” Targets Users in JapanSecurityWeek
A new banking Trojan dubbed “Brolux” has been spotted targeting online banking users in Japan, researchers at ESET have warned.
newswww.securityweek.comOct 15, 2015, 2:14 PM - Thousands of WordPress sites host Neutrino Exploit KitSecurity Affairs
Experts from security company Zscaler have uncovered a malware campaign which relies on thousands of hijacked WordPress sites hosting the Neutrino Exploit Kit. According to the experts at the Zscaler security firm, cybercriminals have compromised more than 2,600 WordPress websites over the past month and deployed malicious iframes on 4,200 distinct pages. The criminals exploited […]
newssecurityaffairs.comAug 22, 2015, 6:23 AM - Blue Termite APT group focuses on Japanese organizationsSecurity Affairs
Security experts at Kaspersky Lab have analyzed the cyber attacks run by the Blue Termite APT, a hacking crew group focused on Japanese organizations. According to the experts at Kaspersky security firm, an ATP group dubbed Blue Termite has been active since at least November 2013 focusing its attacks on Japanese organizations. The Blue Termite APT […]
newssecurityaffairs.comAug 21, 2015, 7:51 AM - Blue Termite APT Targets Japanese OrganizationsSecurityWeek
Kaspersky Lab has analyzed the activities of Blue Termite, an advanced persistent threat (APT) group focusing its efforts on Japanese organizations.
newswww.securityweek.comAug 20, 2015, 3:08 PM Emissary Panda Using Hacking Team Exploits to Deliver RAT The Chinese advanced persistent threat (APT) group known as Emissary Panda and Threat Group 3390 has been using Hacking Team’s Flash Player exploits in its operations.
newswww.securityweek.comAug 19, 2015, 7:18 AM- Zero-day disclosure-to-weaponization period cut in halfHelp Net Security
There’s no doubt about it: the batch of stolen information leaked in the wake of the Hacking Team breach was a boon for exploit kit developers.Not only did it contain a number of exploits for previously unknown zero-day vulnerabilities, but they were accompanied with instructions that allowed them to minimize the time it took them to implement the exploit in their kits.The first of those exploits – for CVE-2015-5119 – was found on the same … More →
newswww.helpnetsecurity.comAug 6, 2015, 6:11 AM LAS VEGAS – Earlier this year, a disgruntled reseller leaked the source code for version 2.0 of the RIG exploit kit. Since then, the RIG’s author has released version 3.0, which was recently discovered by researchers from Trustwave. The latest version uses malvertising in order to deliver a majority of its traffic, infecting some 1.25 […]
newswww.csoonline.comAug 3, 2015, 4:00 PMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box. Russian APT launched a new phishing campaign on the Pentagon Dead NIS agent left note denying spying on SK population Microsoft to spoofed Skype users: Change your account passwords […]
newssecurityaffairs.comJul 26, 2015, 1:01 PMOn the day Adobe patched two of the Flash Player zero-day vulnerabilities uncovered following the Hacking Team breach, FireEye researchers noticed that one of the flaws had been used in an attack aimed at organizations in Japan.
newswww.securityweek.comJul 20, 2015, 5:06 PM- Phishing campaigns target US government agencies exploiting Hacking Team flaw CVE-2015-5119Security Affairs
A recent FBI memo warns phishing attacks targeted government agencies trying to exploit the CVE-2015-5119 vulnerability linked to Hacking Team data breach. According to an FBI warning, hackers have targeted US Government agencies using a recently patched Adobe Flash vulnerability (CVE-2015-5119). The Adobe Flash vulnerability was one of the flaws discovered by analyzing the 400Gb archive […]
newssecurityaffairs.comJul 20, 2015, 7:29 AM In an alert on Friday, the FBI has issued a warning about an active phishing campaign targeting various government agencies in the U.S. The alert says phishing emails in July and those from June targeted an Adobe Flash vulnerability discovered in the Hacking Team files. The FBI memo says the vulnerability being leveraged in the […]
newswww.csoonline.comJul 17, 2015, 6:39 PMMicrosoft on Tuesday patched several memory corruption vulnerabilities in Office, including one that had been exploited in the wild by a well known advanced persistent threat (APT) actor.
newswww.securityweek.comJul 16, 2015, 5:06 PMAdobe Releases Security Updates for Flash Player, Acrobat, Reader, Shockwave Player
newswww.securityweek.comJul 14, 2015, 4:21 PMA notorious cyber espionage group has been using a Java zero-day exploit in attacks aimed at the armed forces of a NATO member country and a defense organization based in the United States, Trend Micro reported over the weekend.
newswww.securityweek.comJul 13, 2015, 10:33 AMResearchers have identified exploits for two new Adobe Flash Player zero-day vulnerabilities in the Hacking Team leak . Adobe has promised to patch the newly discovered bugs sometime this week.
newswww.securityweek.comJul 13, 2015, 8:20 AM- Two more Flash 0-day exploits found in Hacking Team leak, one already exploited in the wildHelp Net Security
Exploits for two more Adobe Flash 0-days have been found in the leaked Hacking Team data. The existence of the vulnerabilities has been acknowledged by Adobe with a security advisory.They affect all versions of Adobe Flash Player for Windows, OS X and Linux, and can be exploited to take control of vulnerable systems.CVE-2015-5122 was reported by FireEye researcher Dhanesh Kizhakkinan. He says the exploit for the flaw is well written and uses constructs for exploiting … More →
newswww.helpnetsecurity.comJul 12, 2015, 11:30 PM - Week in review: HackingTeam breach and consequences, and Android games unmasked as phishing toolsHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles:Hacking Team hacked, 400GB+ of company documents and emails leakedHacking Team, the (in)famous Italian company that provides offensive intrusion and surveillance software to governments, intelligence and law enforcement agencies around the world, has been hacked. Let’s Encrypt CA releases transparency report before its first certificateThe non-profit CA launched by the EFF, Mozilla and several other businesses and organizations is determined to gain and … More →
newswww.helpnetsecurity.comJul 12, 2015, 10:45 PM - A new Zero-Day Vulnerability arises from Hacking Team hackSecurity Affairs
Security Researchers at Trend Micro have discovered a second Zero-Day Vulnerability that arises from Hacking Team cyber attack. Just Three days ago, Adobe released a new version of Flash to patch the zero-day vulnerability that was disclosed as part of the Hacking Team hack. Security experts at Trend Micro confirmed that the Adobe Flash vulnerability […]
newssecurityaffairs.comJul 12, 2015, 6:55 AM - Wekby APT attacks leverage Hacking Team exploitsSecurity Affairs
According to the experts at Volexity the Flash Player exploit has been leveraged in spear phishing campaign launched by the Wekby APT. As anticipated, several criminal gangs included the code for the exploitation of CVE-2015-5119 vulnerability in their exploit kits, let’s remember that the exploits code was disclosed as the result of the attack against the Hacking […]
newssecurityaffairs.comJul 11, 2015, 5:08 AM The Adobe Flash Player exploit stolen by hackers from spyware maker Hacking Team has been leveraged by advanced persistent threat (APT) groups, according to security solutions provider Volexity.
newswww.securityweek.comJul 10, 2015, 1:20 PMOn July 8, 2015, Unit 42 used the AutoFocus Threat Intelligence service to locate and investigate activity consistent with a spear-phishing attack targeting the US Government. The attack exploited an Adobe Flash vulnerability that stems from the zero-day vulnerabilities exposed from this month’s Hacking Team data breach. The spear-phishing attack used a link to a
vendorunit42.paloaltonetworks.comJul 10, 2015, 8:36 AM- DirectRev Malvertising Uses Self Sufficient Flash 0DayMalwarebytes Labs
We have been observing a surge in drive-by download attacks since the recent Flash zero-day (now patched). This is due to the…
newswww.malwarebytes.comJul 9, 2015, 5:00 PM - Hacking Team Zero-Day tied to attacks In Korea and JapanSecurity Affairs
Security experts at Trend Micro revealed that one of the exploits discovered in the Hacking Team package tied to Attacks In Korea and Japan. Following the recent hack of the popular surveillance firm Hacking Team, the experts started the analysis of the material leaked online by the attackers. The package leaked online include also a number […]
newssecurityaffairs.comJul 9, 2015, 1:44 PM The Adobe Flash Player zero-day leaked earlier this week was used in limited attacks before the data breach suffered by spyware maker Hacking Team came to light.
newswww.securityweek.comJul 9, 2015, 8:54 AM- Hacking Team’s Flash 0-day exploit used against Korean targets before it was leakedHelp Net Security
The Adobe Flash zero-day (CVE-2015-5119) exploit found in the Hacking Team’s leaked data has already been added to several exploit kits, but Trend Micro researchers have found evidence of it being used before the data was leaked.Flagged by the company’s Smart Protection Network, it was apparently used to compromise a number of South Korean targets and a Japanese one.“In late June, we learned that a user in Korea was the attempted target of various exploits, … More →
newswww.helpnetsecurity.comJul 9, 2015, 3:13 AM As it promised on Tuesday, Adobe has issued an emergency update for Flash Player to patch a zero-day vulnerability whose existence came to light after hackers breached the systems of surveillance software maker Hacking Team.
newswww.securityweek.comJul 8, 2015, 10:30 AMThere have been additional developments in the Hacking Team story, the latest being that the Adobe Flash vulnerability discovered in the 400GB cache of documents has been picked up by the Neutrino and Angler exploit kits. [See Also: In Pictures: Hacking Team’s hack curated] The Flash exploit was used by Hacking Team for demos, and […]
newswww.csoonline.comJul 8, 2015, 10:22 AMThe Adobe Flash Player zero-day exploit discovered by researchers in the Hacking Team leak has been added to several exploit kits.
newswww.securityweek.comJul 8, 2015, 9:12 AMHuman rights and privacy activists and journalists are actively reviewing the data stolen in the Hacking Team breach.Reporters of The Intercept have concentrated on going through the leaked emails and have revealed the company’s dealings with many countries with dubious human rights records. These recent discoveries have spurred Marietje Schaake, a Dutch member of the European Parliament, to ask that the European Commission investigate whether Hacking Team has violated EU sanctions regimes by selling its … More →
newswww.helpnetsecurity.comJul 8, 2015, 12:17 AM- Hacking Team Leak Exposes New Flash Player Zero DayMalwarebytes Labs
Update (07/07 11:55 AM PT): Adobe released a security bulletin about this vulnerability which is assigned CVE-2015-5119. A fix is scheduled for…
newswww.malwarebytes.comJul 6, 2015, 5:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2015-7645CVSS 7.8 · High
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code…
KEV listed35 mentions - CVE-2015-3113CVSS 9.8 · Critical
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attac…
- CVE-2015-3043CVSS 9.8 · Critical
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cau…
- CVE-2015-8651CVSS 8.8 · High
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Ado…
- CVE-2014-0502CVSS 8.8 · High
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR…
- CVE-2014-0497CVSS 9.8 · Critical
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote att…