VDB
CVE-2015-0310
CVE-2015-0310
PUBLISHED
KEV
CVSS 7.800000190734863 HIGH
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
EPSS 15.10% · 96.6th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
15.10%
96.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | flashplugin-nonfree | 0, 11.2.202.310ubuntu1, 11.2.202.327ubuntu0.13.10.1 |
Timeline
- Nov 14, 2014 CVE Published
- Jan 16, 2015 VulnCheck KEV Exploitation
- Jan 22, 2015 PoC Published
- Jan 23, 2015 VulnCheck KEV Exploitation
- Jan 27, 2015 VulnCheck KEV Exploitation
- Dec 15, 2015 VulnCheck KEV Exploitation
- Aug 17, 2021 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- May 25, 2022 CISA KEV Added
- May 25, 2022 VulnCheck KEV Exploitation
- Sep 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2015-0310 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2015-0310 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory