← Back to CVE List
Vulnerability Intelligence Report
Adobe Flash Player Use-After-Free Vulnerability

CVE-2015-5123

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:18.49%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-416 ↗CWE-416 Use After Free

Affected Products & Versions

Vendor Product Affected Versions
redhat enterprise_linux_desktop 5.0, 6.0
redhat enterprise_linux_server 5.0, 6.0
redhat enterprise_linux_server_eus 6.6
redhat enterprise_linux_workstation 5.0, 6.0
opensuse evergreen 11.4
suse linux_enterprise_desktop 11, 12
suse linux_enterprise_workstation_extension 12
adobe flash_player all
linux linux_kernel all
adobe flash_player_desktop_runtime all
apple macos all
microsoft windows all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
18.493%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2015-06-26T00:00:00
Published2015-07-14T10:00:00
Patch Date2015-07-10
Last Updated2025-11-17T19:54:01

LINK COPIED TO CLIPBOARD