CVE-2015-3113

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
23/06/2015
Last modified:
17/11/2025

Description

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 13.0.0.296 (excluding)
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 14.0.0.125 (including) 18.0.0.194 (excluding)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 11.2.202.468 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:-:*:*:*:*:*:*
cpe:2.3:a:hp:insight_orchestration:*:*:*:*:*:*:*:* 7.5.0 (excluding)
cpe:2.3:a:hp:system_management_homepage:*:*:*:*:*:*:*:* 7.5.0 (excluding)
cpe:2.3:a:hp:systems_insight_manager:*:*:*:*:*:*:*:* 7.5 (excluding)
cpe:2.3:a:hp:version_control_agent:*:*:*:*:*:*:*:* 7.5.0 (excluding)


References to Advisories, Solutions, and Tools