VDB
CVE-2018-15982
CVE-2018-15982
PUBLISHED
KEV
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
EPSS 93.60% · 99.8th percentile
Risk Scores
EPSS Score
93.60%
99.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | flashplugin-nonfree | 11.2.202.548ubuntu0.14.04.1, 11.2.202.310ubuntu1, 11.2.202.332ubuntu1 |
| Ubuntu:18.04:LTS | flashplugin-nonfree | 28.0.0.137ubuntu1, 28.0.0.161ubuntu1, 28.0.0.161ubuntu3 |
| Ubuntu:16.04:LTS | flashplugin-nonfree | 26.0.0.137ubuntu0.16.04.1, 26.0.0.151ubuntu0.16.04.1, 27.0.0.159ubuntu0.16.04.1 |
Exploit Intelligence
- Flash sources for CVE-2018-15982 used by NK (github-poc-repo)
- Flash sources for CVE-2018-15982 used by NK (github-poc-repo)
- Flash sources for CVE-2018-15982 used by NK (github-poc-repo)
- Flash sources for CVE-2018-15982 used by NK (github-poc-repo)
- Flash sources for CVE-2018-15982 used by NK (github-poc-repo)
- Flash sources for CVE-2018-15982 used by NK (github-poc-repo)
- Flash sources for CVE-2018-15982 used by NK (github-poc-repo)
- Flash 2018-15982 UAF (github-poc-repo)
- Flash 2018-15982 UAF (github-poc-repo)
- Flash 2018-15982 UAF (github-poc-repo)
…and 156 more exploits
Timeline
- Jan 19, 1970 VulnCheck XDB Entry
- Jul 5, 2015 VulnCheck KEV Exploitation
- Jul 21, 2015 VulnCheck KEV Exploitation
- Aug 10, 2015 VulnCheck KEV Exploitation
- Feb 3, 2016 VulnCheck KEV Exploitation
- Jan 9, 2017 VulnCheck KEV Exploitation
- Feb 4, 2018 VulnCheck KEV Exploitation
- Jun 20, 2018 VulnCheck KEV Exploitation
- Sep 5, 2018 VulnCheck KEV Exploitation
- Dec 5, 2018 PoC Published
- Dec 6, 2018 PoC Published
- Dec 24, 2018 PoC Published
References
- https://ubuntu.com/security/CVE-2018-15982 third-party-advisory
- https://rhn.redhat.com/errata/RHSA-2018-3795.html third-party-advisory
- https://helpx.adobe.com/security/products/flash-player/apsb18-42.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-15982 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory