CVE Database
/

CVE-2015-5123

Back to search

CVE-2015-5123

Published: Jul 14, 2015

Modified: Nov 17, 2025

PUBLISHED

Description

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

VendorProductVersions

n/a

n/a

affected
n/a

References

1032890
vdb-entry
x_refsource_SECTRACK
SUSE-SU-2015:1255
vendor-advisory
x_refsource_SUSE
HPSBMU03409
vendor-advisory
x_refsource_HP
TA15-195A
third-party-advisory
x_refsource_CERT
VU#918568
third-party-advisory
x_refsource_CERT-VN
SUSE-SU-2015:1258
vendor-advisory
x_refsource_SUSE
GLSA-201508-01
vendor-advisory
x_refsource_GENTOO
HPSBHF03509
vendor-advisory
x_refsource_HP
RHSA-2015:1235
vendor-advisory
x_refsource_REDHAT
SSRT102253
vendor-advisory
x_refsource_HP
75710
vdb-entry
x_refsource_BID
openSUSE-SU-2015:1267
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now