← All CVEs

CVE-2015-0310

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-05-25Remediation due 2022-06-15

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

7.8
CVSS
15.1%
EPSS (exploit prob.)
97th
EPSS percentile
2015-01-23
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
adobeflash_player< 11.2.202.438
linuxlinux_kernelall versions
adobeflash_player< 13.0.0.262
adobeflash_player>= 14.0, < 16.0.0.287
applemac_os_xall versions
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-0310