CVE detail
CVE-2015-0359
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- New Terror Exploit Kit EmergesSecurityWeek
After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.
newswww.securityweek.comJan 10, 2017, 4:59 PM - Flash Flaws Most Common in Exploit Kits: ReportSecurityWeek
Eight of the top ten vulnerabilities used by exploit kits this year affect Adobe Flash Player, a new report from threat intelligence company Recorded Future shows.
newswww.securityweek.comNov 10, 2015, 3:20 PM - Elusive HanJuan EK Drops New Tinba Version (updated)Malwarebytes Labs
Update 07/03/15: AdFly contacted us and we are publishing their statement below: We are sorry for the inconvenience but this is…
newswww.malwarebytes.comJun 23, 2015, 5:00 PM Just days after the developers of the Angler exploit kit started leveraging a recently patched Flash Player vulnerability to distribute malware, an exploit for the same security bug was also added to the Magnitude, Neutrino and Nuclear Pack exploit kits.
newswww.securityweek.comJun 2, 2015, 11:34 AMWhat follows is a detailed analysis of the root cause of a vulnerability we call CVE-2015-X, as well as a step-by-step explanation of how to trigger it. For more on Flash vulnerabilities, we also invite you to read "The Latest UAF Vulnerabilities in Exploit Kits," published May 28 by Tao Yan. Not too long ago we
vendorunit42.paloaltonetworks.comJun 1, 2015, 8:20 PMThe authors of the popular Angler exploit kit integrated an exploit for a Flash Player flaw fixed by Adobe just a couple of weeks ago. The creators of the popular Angler exploit KIT are known for being quick in integrating and exploiting zero-day vulnerabilities, this time they added an exploit related with the Flash player, […]
newssecurityaffairs.comMay 29, 2015, 9:44 AMIntroduction Recently, several popular exploit kits, including Angler, Flash EK, SweetOrange, Fiesta andNeutrino[1], have included several use-after-free (UAF) vulnerabilities in Adobe Flash to exploit victims’ browsers. Previously, these exploit kits typically used out-of-bounds access (OBA) vulnerabilities in Adobe Flash, as these types of vulnerabilities can be exploited universally and stably [2], and require less effort
vendorunit42.paloaltonetworks.comMay 28, 2015, 1:00 PM- Adobe fixes Flash Player zero-day exploited in the wildHelp Net Security
Adobe released a new version of Flash Player (17.0.0.169) for Windows and Macintosh, and for Linux (11.2.202.457). These security updates fix a host of critical vulnerabilities – 22 in all – most of which could lead to code execution and an attacker taking control of the affected system: Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043) A type confusion vulnerability that could lead … More →
newswww.helpnetsecurity.comApr 15, 2015, 3:50 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2019-7108CVSS 7.5 · High
Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead…
- CVE-2019-7096CVSS 9.8 · Critical
Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successful exploitation could lead to…
- CVE-2019-7837CVSS 8.8 · High
Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to a…
- CVE-2018-15983CVSS 7.8 · High
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to priv…
- CVE-2018-15982CVSS 7.8 · High
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2018-15981CVSS 9.8 · Critical
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.