CVE detail
CVE-2015-0336
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
A group of Georgia Tech researchers have been awarded $100,000 by Facebook for coming up with a novel technique for detecting bad casting vulnerabilities.
newswww.securityweek.comAug 14, 2015, 5:15 PM- A variant of the Angler Exploit Kit used to infect PoS SystemsSecurity Affairs
Experts at Trend Micro discovered that cyber criminals are exploiting the popular Angler Exploit kit to find and infect PoS systems. The popular Angler Exploit kit is used by criminal crews to find and infect PoS systems, this is the last disconcerting discovery made by the experts at Trend Micro. The security researcher Anthony Joe […]
newssecurityaffairs.comAug 1, 2015, 8:04 AM An exploit for a Flash Player vulnerability patched recently by Adobe has already been integrated into at least two exploit kits, security firms reported.
newswww.securityweek.comMar 23, 2015, 4:56 PMCybercriminals are exploiting newly patched vulnerabilities faster, a sign that users and companies need to improve their software updating habits. Researchers from both Malwarebytes and FireEye reported Thursday that drive-by download attacks using the Nuclear Exploit Kit target a vulnerability that was patched last week in Flash Player. The flaw, which is tracked as CVE-2015-0336, […]
newswww.csoonline.comMar 20, 2015, 5:33 PM- Nuclear EK leverages recently patched Flash vulnerabilityMalwarebytes Labs
Back in October 2014, we wrote an article about a particular malware campaign we nicknamed ‘EITest’.The actors behind it were using…
newswww.malwarebytes.comMar 18, 2015, 5:00 PM - Adobe issued the updates for 11 Critical VulnerabilitiesSecurity Affairs
Adobe released security updates for Adobe Flash Player to fix 11 Critical Vulnerabilities, most of them Remote Code Execution flaws. Adobe has issued a critical update for the Flash Player product that fixes set of 11 critical security vulnerabilities in its software. The update is classified as critical because most of the security flaws could […]
newssecurityaffairs.comMar 15, 2015, 1:12 PM Adobe has released security updates to patch nearly a dozen serious vulnerabilities affecting the Windows, Mac and Linux versions of Flash Player.
newswww.securityweek.comMar 13, 2015, 9:02 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2019-7108CVSS 7.5 · High
Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead…
- CVE-2019-7096CVSS 9.8 · Critical
Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successful exploitation could lead to…
- CVE-2019-7837CVSS 8.8 · High
Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to a…
- CVE-2018-15983CVSS 7.8 · High
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to priv…
- CVE-2018-15982CVSS 7.8 · High
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2018-15981CVSS 9.8 · Critical
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.