CVE detail
CVE-2015-5123
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Exploit Kits Mutate, Increase Activity: ReportSecurityWeek
Security researchers have observed an increase in exploit kit (EK) activity in the beginning of this year, coupled with a series of mutations, which include spreading more malware, Heimdal Security reports.
newswww.securityweek.comJan 6, 2016, 6:21 PM Emissary Panda Using Hacking Team Exploits to Deliver RAT The Chinese advanced persistent threat (APT) group known as Emissary Panda and Threat Group 3390 has been using Hacking Team’s Flash Player exploits in its operations.
newswww.securityweek.comAug 19, 2015, 7:18 AMOn the day Adobe patched two of the Flash Player zero-day vulnerabilities uncovered following the Hacking Team breach, FireEye researchers noticed that one of the flaws had been used in an attack aimed at organizations in Japan.
newswww.securityweek.comJul 20, 2015, 5:06 PMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box. A new Zero-Day Vulnerability arises from Hacking Team hack Hacking Team Another Flash Zero-Day: CVE-2015-5122 Hacking Team by Numbers – The Infographic Hacking Team chief: Were the GOOD GUYS […]
newssecurityaffairs.comJul 19, 2015, 11:05 AMAdobe Releases Security Updates for Flash Player, Acrobat, Reader, Shockwave Player
newswww.securityweek.comJul 14, 2015, 4:21 PM- Hacking Team, the third Flash Zero-Day is out: CVE-2015-5123Security Affairs
Following the Hacking Team data breach, the security researchers discovered the third Adobe Flash Player zero-day vulnerability. A third Adobe Flash Player zero-day has been discovered since the HackingTeam breach. Thanks to the breach of the Hacking Team‘s private files, the third Adobe Flash zero-day has been made publicly accessible. “After two Adobe Flash player zero-days disclosed […]
newssecurityaffairs.comJul 14, 2015, 5:45 AM Recently breached surveillance software maker, Hacking Team, had access to three different exploits for previously unknown vulnerabilities in Flash Player. All of them are now out in the open, putting Internet users at risk. Milan-based Hacking Team develops and sells surveillance software to government agencies from around the world. On July 5, a hacker released […]
newswww.csoonline.comJul 13, 2015, 12:54 PMResearchers have identified exploits for two new Adobe Flash Player zero-day vulnerabilities in the Hacking Team leak . Adobe has promised to patch the newly discovered bugs sometime this week.
newswww.securityweek.comJul 13, 2015, 8:20 AM- Two more Flash 0-day exploits found in Hacking Team leak, one already exploited in the wildHelp Net Security
Exploits for two more Adobe Flash 0-days have been found in the leaked Hacking Team data. The existence of the vulnerabilities has been acknowledged by Adobe with a security advisory.They affect all versions of Adobe Flash Player for Windows, OS X and Linux, and can be exploited to take control of vulnerable systems.CVE-2015-5122 was reported by FireEye researcher Dhanesh Kizhakkinan. He says the exploit for the flaw is well written and uses constructs for exploiting … More →
newswww.helpnetsecurity.comJul 12, 2015, 11:30 PM - Hacking Team Another Flash Zero-Day: CVE-2015-5122Security Affairs
Following the Hacking Team data breach, yet another Adobe Flash Player zero-day vulnerability has been found actively exploited in-the-wild. Another Flash Zero-Day: CVE-2015-5122 Yet another Adobe Flash Player zero-day has been found actively exploited in-the-wild. Thanks to the breach of the HackingTeam’s private files, another Adobe Flash zero-day has been made publicly accessible and hackers […]
newssecurityaffairs.comJul 12, 2015, 9:54 AM - A new Zero-Day Vulnerability arises from Hacking Team hackSecurity Affairs
Security Researchers at Trend Micro have discovered a second Zero-Day Vulnerability that arises from Hacking Team cyber attack. Just Three days ago, Adobe released a new version of Flash to patch the zero-day vulnerability that was disclosed as part of the Hacking Team hack. Security experts at Trend Micro confirmed that the Adobe Flash vulnerability […]
newssecurityaffairs.comJul 12, 2015, 6:55 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2015-5122CVSS 9.8 · Critical
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through…
- CVE-2015-5119CVSS 9.8 · Critical
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows…
- CVE-2016-4156CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4148CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4147CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4146CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…