CVE-2015-0310

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
Severity
UNKNOWN
AV:N/AC:L/Au:N/C:C/I:C/A:C
Atk. Vector
NETWORK
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
adobeflash_player
𝑥
≤ 11.2.202.429
adobeflash_player
𝑥
≤ 13.0.0.260
adobeflash_player
14.0.0.125
adobeflash_player
14.0.0.145
adobeflash_player
14.0.0.176
adobeflash_player
14.0.0.179
adobeflash_player
15.0.0.152
adobeflash_player
15.0.0.167
adobeflash_player
15.0.0.189
adobeflash_player
15.0.0.223
adobeflash_player
15.0.0.239
adobeflash_player
15.0.0.246
adobeflash_player
16.0.0.235
adobeflash_player
16.0.0.257
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
utopic
Fixed 11.2.202.429-0utopic1
released
trusty
Fixed 11.2.202.429-0trusty1
released
precise
Fixed 11.2.202.429-0precise1
released
lucid
ignored
flashplugin-nonfree
utopic
Fixed 11.2.202.429ubuntu0.14.10.1
released
trusty
Fixed 11.2.202.429ubuntu0.14.04.1
released
precise
Fixed 11.2.202.429ubuntu0.12.04.1
released
lucid
ignored
Common Weakness Enumeration