flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19)
Published Jul 9, 2018 ·Due Jun 13, 2022
7.8
HIGHCVSS 3.1
EPSS 25.06%
Description
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Affected products
- Vendor n/a Product Adobe Flash Player 29.0.0.171 and earlier versions Defaultn/a
- Version Adobe Flash Player 29.0.0.171 and earlier versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Adobe Flash Player 29.0.0.171 and earlier versions | n/a |
|
Configuration 1
- ≤ 29.0.0.171
Configuration 2
- ≤ 29.0.0.171
Configuration 3
- ≤ 29.0.0.171
- ≤ 29.0.0.171
Running on/with
- n/a
- n/a
Configuration 4
- 6.0
- 6.0
- 6.0
No data.
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:30.0.0.113-1.el6_9
Fixed · RHSA-2018:1827
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:30.0.0.113-1.el6_9 | Fixed | RHSA-2018:1827 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
May 23, 2022
Patch Due
Jun 13, 2022
Required Action
The impacted product is end-of-life and should be disconnected if still in use.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Nov 17, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (43 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 25.06% (0.25059) | 97.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 25.35% (0.25353) | 97.66th | v5 (v2026.06.15) |
| Mar 17, 2026 | 47.14% (0.47145) | 97.64th | v4 (v2025.03.14) |
| Feb 17, 2026 | 45.01% (0.45010) | 97.50th | v4 (v2025.03.14) |
| Dec 30, 2025 | 48.48% (0.48477) | 97.63th | v4 (v2025.03.14) |
| Nov 19, 2025 | 44.54% (0.44541) | 97.41th | v4 (v2025.03.14) |
| Nov 18, 2025 | 32.99% (0.32987) | 96.66th | v4 (v2025.03.14) |
| Nov 15, 2025 | 43.64% (0.43643) | 97.36th | v4 (v2025.03.14) |
| Oct 24, 2025 | 42.23% (0.42234) | 97.28th | v4 (v2025.03.14) |
| Oct 22, 2025 | 37.19% (0.37189) | 96.95th | v4 (v2025.03.14) |
| Oct 21, 2025 | 31.09% (0.31093) | 96.50th | v4 (v2025.03.14) |
| Oct 17, 2025 | 33.27% (0.33266) | 96.68th | v4 (v2025.03.14) |
| Oct 12, 2025 | 34.60% (0.34599) | 96.79th | v4 (v2025.03.14) |
| Sep 27, 2025 | 37.38% (0.37375) | 97.08th | v4 (v2025.03.14) |
| Aug 24, 2025 | 36.01% (0.36006) | 96.96th | v4 (v2025.03.14) |
| May 31, 2025 | 37.38% (0.37375) | 96.97th | v4 (v2025.03.14) |
| Apr 17, 2025 | 47.24% (0.47244) | 97.48th | v4 (v2025.03.14) |
| Mar 30, 2025 | 42.81% (0.42806) | 97.21th | v4 (v2025.03.14) |
| Mar 29, 2025 | 68.48% (0.68478) | 98.09th | v4 (v2025.03.14) |
| Mar 17, 2025 | 42.81% (0.42806) | 97.17th | v4 (v2025.03.14) |
| Feb 9, 2025 | 29.77% (0.29769) | 96.97th | v3 (v2023.03.01) |
| Jan 2, 2025 | 15.17% (0.15166) | 95.83th | v3 (v2023.03.01) |
| Dec 17, 2024 | 8.59% (0.08589) | 94.47th | v3 (v2023.03.01) |
| Oct 12, 2024 | 4.12% (0.04119) | 92.34th | v3 (v2023.03.01) |
| May 18, 2024 | 3.10% (0.03103) | 91.04th | v3 (v2023.03.01) |
| Mar 24, 2024 | 4.00% (0.04005) | 91.85th | v3 (v2023.03.01) |
| Feb 26, 2024 | 2.32% (0.02316) | 89.40th | v3 (v2023.03.01) |
| Jan 9, 2024 | 2.74% (0.02743) | 89.47th | v3 (v2023.03.01) |
| Nov 30, 2023 | 2.81% (0.02806) | 89.55th | v3 (v2023.03.01) |
| Nov 8, 2023 | 3.14% (0.03142) | 90.01th | v3 (v2023.03.01) |
| Oct 1, 2023 | 4.38% (0.04385) | 91.36th | v3 (v2023.03.01) |
| Sep 5, 2023 | 2.24% (0.02241) | 88.14th | v3 (v2023.03.01) |
| Sep 4, 2023 | 13.68% (0.13682) | 94.92th | v3 (v2023.03.01) |
| Aug 26, 2023 | 2.24% (0.02241) | 88.13th | v3 (v2023.03.01) |
| May 31, 2023 | 2.67% (0.02671) | 88.87th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.38% (0.02380) | 88.13th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.10% (0.03097) | 83.82th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.10% (0.03097) | 82.23th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.10% (0.03097) | 64.90th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.39% (0.09393) | 86.77th | v1 |
| Jan 6, 2022 | 9.39% (0.09393) | 86.62th | v1 |
| Sep 1, 2021 | 9.39% (0.09393) | 94.01th | v1 |
| Apr 14, 2021 | 9.39% (0.09393) | 0.00th | v1 |
References (12)
- http://www.securityfocus.com/bid/104412 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041058 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1827 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-5002 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1588501 Issue Tracking
- https://github.com/cisagov/vulnrichment/issues/196 issue-trackingIssue Tracking
- https://helpx.adobe.com/security/products/flash-player/apsb18-19.html x_refsource_MISCPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-5002
- https://security.gentoo.org/glsa/201806-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-5002 government-resourceThird Party AdvisoryUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2018-5002
Change history (0)
No recorded changes yet.