Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

191–193 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#191
post #120

Earlier quoted context omitted.

data: I grabbed all 500+ records and counted, by month, those with severity 10 (column 10) and severity >= 7 (column 7). Rows is the # of cve records for that month. it's not awesome month rows 10 7 2015-07 35 28 29 2015-06 14 7 7 2015-05 17 10 10 2015-04 22 19 19 2015-03 11 7 9 2015-02 19 19 19 2015-01 12 9 11 2014-12 6 5 5 2014-11 19 16 18 2014-10 3 3 3 2014-09 12 11 12 2014-08 8 7 7 2014-07 3 0 2 2014-06 6 1 3 201…

Vulnerabilities increase and usage decreases. I wonder if an economically sensible decision should be to EOL Flash soon. Are they still doing any money out of it?

I answer to myself because I just read this http://www.theverge.com/2015/7/13/8948459/adobe-flash-insecu... from Facebook's CSO.

"It is time for Adobe to announce the end-of-life date for Flash and to ask the browsers to set killbits on the same day. — Alex Stamos (@alexstamos) July 12, 2015"

Re: Two more Flash 0-days emerge in Hacking Team leak

#193
post #163

0-day exploits? I though that flash had been discontinued years ago. The last release I've found is 11.2, which seems to be years old and the last ever.

http://www.adobe.com/software/flash/about/

Huh, I hadn't researched this before, but it looks like flash for Linux has been frozen for years, while the windows and OS X releases keep getting updates.

So I guess Linux users are immute to this new zero-day?

Post reply on HN