VDB

CVE-2018-4877

CVE-2018-4877 PUBLISHED

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.

EPSS 5.04% · 89.9th percentile

Risk Scores

EPSS Score
5.04%
89.9th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSflashplugin-nonfree0, 11.2.202.332ubuntu1, 11.2.202.335ubuntu1
Ubuntu:16.04:LTSflashplugin-nonfree*, 11.2.202.540ubuntu2, 11.2.202.548ubuntu1

Exploit Intelligence

…and 23 more exploits

Timeline

  • Feb 2, 2018 CVE Published
  • Feb 7, 2018 CVE Updated
  • Feb 24, 2018 PoC Published
  • Oct 25, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›