Skip to main content

CVE detail

CVE-2015-5123

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVSS 9.8 · CriticalBuzz score 59.4KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 59.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.9 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
24.9
11 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
11 source links · newest first
  • Security researchers have observed an increase in exploit kit (EK) activity in the beginning of this year, coupled with a series of mutations, which include spreading more malware, Heimdal Security reports.

    newswww.securityweek.comJan 6, 2016, 6:21 PM
  • Emissary Panda Using Hacking Team Exploits to Deliver RAT The Chinese advanced persistent threat (APT) group known as Emissary Panda and Threat Group 3390 has been using Hacking Team’s Flash Player exploits in its operations.

    newswww.securityweek.comAug 19, 2015, 7:18 AM
  • On the day Adobe patched two of the Flash Player zero-day vulnerabilities uncovered following the Hacking Team breach, FireEye researchers noticed that one of the flaws had been used in an attack aimed at organizations in Japan.

    newswww.securityweek.comJul 20, 2015, 5:06 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box. A new Zero-Day Vulnerability arises from Hacking Team hack Hacking Team Another Flash Zero-Day: CVE-2015-5122 Hacking Team by Numbers – The Infographic Hacking Team chief: Were the GOOD GUYS […]

    newssecurityaffairs.comJul 19, 2015, 11:05 AM
  • Adobe Releases Security Updates for Flash Player, Acrobat, Reader, Shockwave Player

    newswww.securityweek.comJul 14, 2015, 4:21 PM
  • Following the Hacking Team data breach, the security researchers discovered the third Adobe Flash Player zero-day vulnerability. A third Adobe Flash Player zero-day has been discovered since the HackingTeam breach. Thanks to the breach of the Hacking Team‘s private files, the third Adobe Flash zero-day has been made publicly accessible. “After two Adobe Flash player zero-days disclosed […]

    newssecurityaffairs.comJul 14, 2015, 5:45 AM
  • Recently breached surveillance software maker, Hacking Team, had access to three different exploits for previously unknown vulnerabilities in Flash Player. All of them are now out in the open, putting Internet users at risk. Milan-based Hacking Team develops and sells surveillance software to government agencies from around the world. On July 5, a hacker released […]

    newswww.csoonline.comJul 13, 2015, 12:54 PM
  • Researchers have identified exploits for two new Adobe Flash Player zero-day vulnerabilities in the Hacking Team leak . Adobe has promised to patch the newly discovered bugs sometime this week.

    newswww.securityweek.comJul 13, 2015, 8:20 AM
  • Exploits for two more Adobe Flash 0-days have been found in the leaked Hacking Team data. The existence of the vulnerabilities has been acknowledged by Adobe with a security advisory.They affect all versions of Adobe Flash Player for Windows, OS X and Linux, and can be exploited to take control of vulnerable systems.CVE-2015-5122 was reported by FireEye researcher Dhanesh Kizhakkinan. He says the exploit for the flaw is well written and uses constructs for exploiting … More →

    newswww.helpnetsecurity.comJul 12, 2015, 11:30 PM
  • Following the Hacking Team data breach, yet another Adobe Flash Player zero-day vulnerability has been found actively exploited in-the-wild. Another Flash Zero-Day: CVE-2015-5122 Yet another Adobe Flash Player zero-day has been found actively exploited in-the-wild. Thanks to the breach of the HackingTeam’s private files, another Adobe Flash zero-day has been made publicly accessible and hackers […]

    newssecurityaffairs.comJul 12, 2015, 9:54 AM
  • Security Researchers at Trend Micro have discovered a second Zero-Day Vulnerability that arises from Hacking Team cyber attack. Just Three days ago, Adobe released a new version of Flash to patch the zero-day vulnerability that was disclosed as part of the Hacking Team hack. Security experts at Trend Micro confirmed that the Adobe Flash vulnerability […]

    newssecurityaffairs.comJul 12, 2015, 6:55 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence