Back to search
CVE-2015-5119
Published: Jul 8, 2015
Modified: Nov 17, 2025
PUBLISHED
Description
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1032809
vdb-entry
x_refsource_SECTRACK
75568
vdb-entry
x_refsource_BID
openSUSE-SU-2015:1207
vendor-advisory
x_refsource_SUSE
TA15-195A
third-party-advisory
x_refsource_CERT
SUSE-SU-2015:1211
vendor-advisory
x_refsource_SUSE
RHSA-2015:1214
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2015:1214
vendor-advisory
x_refsource_SUSE
GLSA-201507-13
vendor-advisory
x_refsource_GENTOO
https://helpx.adobe.com/security/products/flash-player/apsa15-03.html
x_refsource_CONFIRM
VU#561288
third-party-advisory
x_refsource_CERT-VN
https://helpx.adobe.com/security/products/flash-player/apsb15-16.html
x_refsource_CONFIRM
openSUSE-SU-2015:1210
vendor-advisory
x_refsource_SUSE
http://twitter.com/w3bd3vil/statuses/618168863708962816
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now