CVE-2015-5122 is a critical use-after-free vulnerability in Adobe Flash Player's ActionScript 3 implementation, specifically affecting the DisplayObject class across various versions on Windows, OS X, and Linux. This flaw, triggered by improper handling of the opaqueBackground property, allows remote attackers to execute arbitrary code or cause a denial of service. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability has been actively exploited in the wild, with exploit code available in Metasploit and significant community discussion, indicating widespread awareness and potential for continued exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0, <= 13.0.0.302CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
>= 18.0, <= 18.0.0.203CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
>= 18.0, <= 18.0.0.203CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
>= 18.0, <= 18.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
>= 18.0, <= 18.0.0.203CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer_10:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.