6.5
CVSSv3

CVE-2018-5001

Published: 09/07/2018 Updated: 07/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Adobe Flash Player versions 29.0.0.171 and previous versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player_desktop_runtime

adobe flash_player

redhat enterprise linux workstation 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

Vendor Advisories

Synopsis Critical: flash-plugin security update Type/Severity Security Advisory: Critical Topic An update for flash-plugin is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring Syst ...
Adobe Flash Player versions 2900171 and earlier have an Out-of-bounds read vulnerability Successful exploitation could lead to information disclosure ...
An out-of-bounds read has been found in Adobe Flash Player before 3000113, leading to information disclosure ...

Recent Articles

Stop us if you've heard this one: Adobe Flash gets emergency patch for zero-day exploit
The Register • Shaun Nichols in San Francisco • 07 Jun 2018

The internet's screen door gets kicked open once again Nork hackers exploit Flash bug to pwn South Koreans. And Adobe will deal with it next week

Adobe has kicked out an out-of-band update for a security vulnerability in Flash – after learning the bug was being actively exploited in the wild by hackers to hijack PCs. The Photoshop giant said today its Flash Player 30.0.0.113 update should be a top installation priority for Mac, Windows, and Linux systems. One of the vulnerabilities addressed in the patch, CVE-2018-5002, is a remote code execution flaw stemming from a buffer overflow bug. Computer security experts believe the flaw is bei...