Skip to main content

CVE detail

CVE-2018-5002

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS 7.8 · HighBuzz score 63.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 63.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
24.0
10 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
10 source links · newest first
  • Experts believe that the Windows kernel zero-day vulnerability fixed this week by Microsoft with its Patch Tuesday updates has been exploited by several threat actors, including a new group.

    newswww.securityweek.comDec 12, 2018, 8:39 AM
  • #Unit 42 slices and dices CVE-2018-5002, uncovering new #CHAINSHOT malware.

    vendorunit42.paloaltonetworks.comSep 6, 2018, 8:00 PM
  • Cyber criminal organizations and state-sponsored hackers continue to use Exploit kits to compromise targets world worldwide if the use of Exploit kits is decreased across the recent months, some of them were improved by adding the code to exploit recently discovered Flash and Internet Explorer zero-day vulnerabilities. “Since both Flash and the VBScript engine are […]

    newssecurityaffairs.comJun 14, 2018, 7:06 AM
  • Exploit kits (EKs) might not be as dominant as they were several years ago, but they continue to exist and most of them already adopted exploits for recently discovered Flash and Internet Explorer zero-day vulnerabilities.

    newswww.securityweek.comJun 13, 2018, 3:50 PM
  • Exploit kits: Spring 2018 reviewMalwarebytes Labs

    Since our last report on exploit kits, there have been some new developments with the wider adoption of the February Flash…

    newswww.malwarebytes.comJun 11, 2018, 5:00 PM
  • I have been on the road for a few weeks now and surprisingly the topic of discussion has predominantly been patch management. Why is patch such a prevalent topic? Patching responsibility As we near Patch Tuesday this month I wanted to share a few thoughts and observations with you all from my recent travels. Recently I attended RiskSec in New York, and last week I was at Infosecurity Europe. At RiskSec I had the pleasure … More →

    newswww.helpnetsecurity.comJun 11, 2018, 11:45 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online Kindle Edition Paper Copy Once again thank you! Crooks included the code for CVE-2018-8174 IE Zero-Day in the RIG Exploit Kit Impervas […]

    newssecurityaffairs.comJun 10, 2018, 4:57 AM
  • If you’re still using Flash Player, it’s time to update it again – and quickly: Adobe has just patched a critical zero day vulnerability (CVE-2018-5002) actively exploited in the wild. The attacks are “limited, targeted attacks against Windows users,” but updates (v30.0.0.113 for all platforms) are available for Adobe Flash Player for Windows, macOS, Linux and Chrome OS. About CVE-2018-5002 and the attacks It is a stack-based buffer overflow vulnerability that has been independently discovered … More →

    newswww.helpnetsecurity.comJun 8, 2018, 4:34 PM
  • Adobe has recently fixed several vulnerabilities, including the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle East Adobe has released security updates for Flash Player that address four vulnerabilities, including a critical issue (CVE-2018-5002) that has been exploited in targeted attacks mainly aimed at entities in the Middle East. The CVE-2018-5002 vulnerability, reported by researchers at […]

    newssecurityaffairs.comJun 7, 2018, 2:17 PM
  • [Updated] Security updates released by Adobe on Thursday for Flash Player patch four vulnerabilities, including a critical flaw that has been exploited in targeted attacks.

    newswww.securityweek.comJun 7, 2018, 12:25 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence