flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)
Published Jan 18, 2019 ·Due Aug 15, 2022
7.8
HIGHCVSS 3.1
EPSS 89.58%
Description
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected products
No data.
Configuration 1
- ≤ 31.0.0.153
Configuration 2
- ≤ 31.0.0.153
Configuration 3
- ≤ 31.0.0.153
- ≤ 31.0.0.153
Running on/with
- n/a
- n/a
Configuration 4
- 6.0
- 6.0
- 6.0
Configuration 5
- ≤ 31.0.0.108
No data.
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:32.0.0.101-1.el6_10
Fixed · RHSA-2018:3795
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:32.0.0.101-1.el6_10 | Fixed | RHSA-2018:3795 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Feb 15, 2022
Patch Due
Aug 15, 2022
Required Action
The impacted product is end-of-life and should be disconnected if still in use.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 89.58% (0.89581) | 99.78th | v5 (v2026.06.15) |
| Sep 9, 2026 | 89.15% (0.89146) | 99.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 81.84% (0.81844) | 99.60th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.13% (0.93132) | 99.79th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.19% (0.97191) | 99.86th | v3 (v2023.03.01) |
| Jul 20, 2024 | 97.38% (0.97382) | 99.92th | v3 (v2023.03.01) |
| Jun 10, 2024 | 97.38% (0.97376) | 99.91th | v3 (v2023.03.01) |
| May 19, 2024 | 97.41% (0.97405) | 99.92th | v3 (v2023.03.01) |
| Sep 5, 2023 | 97.42% (0.97420) | 99.89th | v3 (v2023.03.01) |
| Sep 4, 2023 | 97.32% (0.97325) | 99.81th | v3 (v2023.03.01) |
| Aug 14, 2023 | 97.42% (0.97420) | 99.89th | v3 (v2023.03.01) |
| Jul 1, 2023 | 97.43% (0.97430) | 99.90th | v3 (v2023.03.01) |
| May 14, 2023 | 97.46% (0.97462) | 99.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.47% (0.97469) | 99.92th | v3 (v2023.03.01) |
| Mar 6, 2023 | 83.58% (0.83578) | 99.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 83.58% (0.83578) | 99.54th | v2 (v2022.01.01) |
| Feb 3, 2022 | 27.91% (0.27907) | 96.29th | v1 |
| Jan 6, 2022 | 27.91% (0.27907) | 96.25th | v1 |
| Sep 1, 2021 | 27.91% (0.27907) | 98.38th | v1 |
| Apr 14, 2021 | 27.91% (0.27907) | 0.00th | v1 |
References (11)
- http://www.securityfocus.com/bid/106116 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3795 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-15982 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1656585 Issue Tracking
- https://github.com/cisagov/vulnrichment/issues/195 issue-trackingIssue Tracking
- https://helpx.adobe.com/security/products/flash-player/apsb18-42.html x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-15982
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-15982 government-resourceThird Party AdvisoryUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2018-15982
- https://www.exploit-db.com/exploits/46051/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106116 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/errata/RHSA-2018:3795 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-15982 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1656585 | Issue Tracking | |
| https://github.com/cisagov/vulnrichment/issues/195 | issue-trackingIssue Tracking | |
| https://helpx.adobe.com/security/products/flash-player/apsb18-42.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-15982 | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-15982 | government-resourceThird Party AdvisoryUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2018-15982 | ||
| https://www.exploit-db.com/exploits/46051/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (3)
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- SSVC automatable changed from yes to
no