Description
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Published: 2015-07-14
Score: 7.8 High
EPSS: 47.6% Moderate
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 04 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-04-13'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Aug 2024 00:00:00 +0000

Type Values Removed Values Added
References

Subscriptions

Adobe Flash Player Flash Player Desktop Runtime
Apple Macos
Linux Linux Kernel
Microsoft Windows
Opensuse Evergreen
Redhat Enterprise Linux Desktop Enterprise Linux Server Enterprise Linux Server Eus Enterprise Linux Workstation Rhel Extras
Suse Linux Enterprise Desktop Linux Enterprise Workstation Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2025-11-17T19:54:01.023Z

Reserved: 2015-06-26T00:00:00.000Z

Link: CVE-2015-5123

cve-icon Vulnrichment

Updated: 2024-08-06T06:32:32.897Z

cve-icon NVD

Status : Deferred

Published: 2015-07-14T10:59:01.337

Modified: 2025-11-17T20:15:46.577

Link: CVE-2015-5123

cve-icon Redhat

Severity : Critical

Publid Date: 2015-07-10T00:00:00Z

Links: CVE-2015-5123 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses