CVE-2015-0310

EUVD-2015-0323
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
adobeflash_player
𝑥
< 11.2.202.438
adobeflash_player
𝑥
< 13.0.0.262
adobeflash_player
14.0 ≤
𝑥
< 16.0.0.287
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
lucid
ignored
precise
Fixed 11.2.202.429-0precise1
released
trusty
Fixed 11.2.202.429-0trusty1
released
utopic
Fixed 11.2.202.429-0utopic1
released
flashplugin-nonfree
lucid
ignored
precise
Fixed 11.2.202.429ubuntu0.12.04.1
released
trusty
Fixed 11.2.202.429ubuntu0.14.04.1
released
utopic
Fixed 11.2.202.429ubuntu0.14.10.1
released