Skip to main content

CVE detail

CVE-2015-5122

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

CVSS 9.8 · CriticalBuzz score 71.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 71.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
28 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
28 source links · newest first
  • About a year ago, we described the Hidden Bee miner delivered by the Underminer Exploit Kit. Hidden Bee has a complex…

    newswww.malwarebytes.comAug 14, 2019, 5:00 PM
  • Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.

    vendorunit42.paloaltonetworks.comDec 27, 2018, 2:00 PM
  • Email Link Analysis from Unit 42 reveals that the United States remain the number one hoster of malicious web addresses for Q2 2018.

    vendorunit42.paloaltonetworks.comSep 5, 2018, 3:12 AM
  • Unit 42 investigates the latest trends in web-based threats.

    vendorunit42.paloaltonetworks.comJun 20, 2018, 2:00 AM
  • Wikileaks revealed that CIA contractor Raytheon Blackbird Technologies was tasked to analyze advanced malware and TTPs used by threat actors in the wild. Wikileaks continues to publish documents from Vault 7 leaks, today the organization has shed light on the collaboration between the US Intelligence agency and tech firms for malware development. The last batch […]

    newssecurityaffairs.comJul 19, 2017, 5:01 PM
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • Experts from Heimdal Security warned of a spike in cyber attacks leveraging the popular RIG Exploit kit to deliver the Cerber Ransomware. The RIG exploit kit is even more popular in the criminal ecosystem, a few days ago security experts at Heimdal Security warned of a spike in cyber attacks leveraging the popular Neutrino and […]

    newssecurityaffairs.comJan 16, 2017, 6:44 AM
  • A newly observed campaign leveraging the RIG exploit kit is targeting outdated versions of popular applications such as Flash, Internet Explorer, or Microsoft Edge to distribute the Cerber ransomware, Heimdal Security warns.

    newswww.securityweek.comJan 15, 2017, 6:55 PM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • Exploit kits: Fall 2016 reviewMalwarebytes Labs

    There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…

    newswww.malwarebytes.comNov 8, 2016, 5:00 PM
  • Malvertising remains a favourite distribution platform for pushing out malware and we typically see certain exploit kits associated with particular campaigns. As…

    newswww.malwarebytes.comAug 9, 2016, 5:00 PM
  • Security experts at Heimdal Security are warning a spike in cyber attacks leveraging the popular Neutrino and RIG exploit kit. Cyber criminals always exploit new opportunities and users’ bad habits, now crooks behind the recent campaigns relying on Neutrino and RIG exploit kits are ramping up attacks against users that haven’s patched their Adobe Flash software. “It […]

    newssecurityaffairs.comJan 12, 2016, 9:35 AM
  • Security researchers have observed an increase in exploit kit (EK) activity in the beginning of this year, coupled with a series of mutations, which include spreading more malware, Heimdal Security reports.

    newswww.securityweek.comJan 6, 2016, 6:21 PM
  • Unconventional Malvertising Attack Uses New TricksMalwarebytes Labs

    A few days ago we spotted an interesting malvertising attack that was unlike others we had seen before. What made it…

    newswww.malwarebytes.comSep 17, 2015, 5:00 PM
  • LAS VEGAS – Earlier this year, a disgruntled reseller leaked the source code for version 2.0 of the RIG exploit kit. Since then, the RIG’s author has released version 3.0, which was recently discovered by researchers from Trustwave. The latest version uses malvertising in order to deliver a majority of its traffic, infecting some 1.25 […]

    newswww.csoonline.comAug 3, 2015, 4:00 PM
  • Popular news site rbc[dot]ua is currently hacked and infecting its visitors via the RIG exploit kit. The majority of the traffic to…

    newswww.malwarebytes.comJul 26, 2015, 5:00 PM
  • On the day Adobe patched two of the Flash Player zero-day vulnerabilities uncovered following the Hacking Team breach, FireEye researchers noticed that one of the flaws had been used in an attack aimed at organizations in Japan.

    newswww.securityweek.comJul 20, 2015, 5:06 PM
  • On July 16, 2015, the Palo Alto Networks Unit 42 threat intelligence team discovered a watering hole attack on the website of a well-known aerospace firm. The website was compromised to launch an apparent watering-hole attack against the company's customers. It was hosting an Adobe Flash exploit targeting one of the newly disclosed vulnerabilities from

    vendorunit42.paloaltonetworks.comJul 20, 2015, 9:32 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box. A new Zero-Day Vulnerability arises from Hacking Team hack Hacking Team Another Flash Zero-Day: CVE-2015-5122 Hacking Team by Numbers – The Infographic Hacking Team chief: Were the GOOD GUYS […]

    newssecurityaffairs.comJul 19, 2015, 11:05 AM
  • Adobe Releases Security Updates for Flash Player, Acrobat, Reader, Shockwave Player

    newswww.securityweek.comJul 14, 2015, 4:21 PM
  • Following the Hacking Team data breach, the security researchers discovered the third Adobe Flash Player zero-day vulnerability. A third Adobe Flash Player zero-day has been discovered since the HackingTeam breach. Thanks to the breach of the Hacking Team‘s private files, the third Adobe Flash zero-day has been made publicly accessible. “After two Adobe Flash player zero-days disclosed […]

    newssecurityaffairs.comJul 14, 2015, 5:45 AM
  • Recently breached surveillance software maker, Hacking Team, had access to three different exploits for previously unknown vulnerabilities in Flash Player. All of them are now out in the open, putting Internet users at risk. Milan-based Hacking Team develops and sells surveillance software to government agencies from around the world. On July 5, a hacker released […]

    newswww.csoonline.comJul 13, 2015, 12:54 PM
  • The huge cache of files recently leaked from Italian surveillance software maker Hacking Team is the gift that keeps on giving for attackers. Researchers sifting through the data found a new exploit for a previously unknown vulnerability in Adobe’s Flash Player. This is the second Flash Player zero-day exploit discovered among the files and the […]

    newswww.csoonline.comJul 13, 2015, 10:00 AM
  • Researchers have identified exploits for two new Adobe Flash Player zero-day vulnerabilities in the Hacking Team leak . Adobe has promised to patch the newly discovered bugs sometime this week.

    newswww.securityweek.comJul 13, 2015, 8:20 AM
  • Exploits for two more Adobe Flash 0-days have been found in the leaked Hacking Team data. The existence of the vulnerabilities has been acknowledged by Adobe with a security advisory.They affect all versions of Adobe Flash Player for Windows, OS X and Linux, and can be exploited to take control of vulnerable systems.CVE-2015-5122 was reported by FireEye researcher Dhanesh Kizhakkinan. He says the exploit for the flaw is well written and uses constructs for exploiting … More →

    newswww.helpnetsecurity.comJul 12, 2015, 11:30 PM
  • Following the Hacking Team data breach, yet another Adobe Flash Player zero-day vulnerability has been found actively exploited in-the-wild. Another Flash Zero-Day: CVE-2015-5122 Yet another Adobe Flash Player zero-day has been found actively exploited in-the-wild. Thanks to the breach of the HackingTeam’s private files, another Adobe Flash zero-day has been made publicly accessible and hackers […]

    newssecurityaffairs.comJul 12, 2015, 9:54 AM
  • Security Researchers at Trend Micro have discovered a second Zero-Day Vulnerability that arises from Hacking Team cyber attack. Just Three days ago, Adobe released a new version of Flash to patch the zero-day vulnerability that was disclosed as part of the Hacking Team hack. Security experts at Trend Micro confirmed that the Adobe Flash vulnerability […]

    newssecurityaffairs.comJul 12, 2015, 6:55 AM
  • Update: 07/15 7 As reported by Kafeine, Magnitude EK is now using this zero-day. Update: 07/14 7 As reported by brooks_li, RIG EK…

    newswww.malwarebytes.comJul 10, 2015, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence