VDB

CVE-2015-0310

CVE-2015-0310 PUBLISHED KEV CVSS 7.800000190734863 HIGH

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

EPSS 15.10% · 96.6th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
15.10%
96.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSflashplugin-nonfree0, 11.2.202.310ubuntu1, 11.2.202.327ubuntu0.13.10.1

Timeline

  • Nov 14, 2014 CVE Published
  • Jan 16, 2015 VulnCheck KEV Exploitation
  • Jan 22, 2015 PoC Published
  • Jan 23, 2015 VulnCheck KEV Exploitation
  • Jan 27, 2015 VulnCheck KEV Exploitation
  • Dec 15, 2015 VulnCheck KEV Exploitation
  • Aug 17, 2021 VulnCheck KEV Exploitation
  • Feb 4, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • May 25, 2022 CISA KEV Added
  • May 25, 2022 VulnCheck KEV Exploitation
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›