← All CVEs

CVE-2015-3043

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-03-03Remediation due 2022-03-24

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

9.8
CVSS
73.9%
EPSS (exploit prob.)
99th
EPSS percentile
2015-04-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
adobeflash_player< 11.2.202.457
linuxlinux_kernelall versions
adobeflash_player< 13.0.0.281
adobeflash_player>= 14.0.0.125, < 17.0.0.169
applemac_os_xall versions
microsoftwindowsall versions
novellsuse_linux_enterprise_desktop11.0
novellsuse_linux_enterprise_desktop12.0
novellsuse_linux_enterprise_workstation_extension12.0
opensuseevergreen11.4
opensuseopensuse13.1
opensuseopensuse13.2
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.6
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus6.6
redhatenterprise_linux_server_from_rhui5.0
redhatenterprise_linux_server_from_rhui6.0
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-3043