CVE-2015-0310

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
adobeCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
adobeflash_player
𝑥
< 11.2.202.438
adobeflash_player
𝑥
< 13.0.0.262
adobeflash_player
14.0 ≤
𝑥
< 16.0.0.287
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
utopic
Fixed 11.2.202.429-0utopic1
released
trusty
Fixed 11.2.202.429-0trusty1
released
precise
Fixed 11.2.202.429-0precise1
released
lucid
ignored
flashplugin-nonfree
utopic
Fixed 11.2.202.429ubuntu0.14.10.1
released
trusty
Fixed 11.2.202.429ubuntu0.14.04.1
released
precise
Fixed 11.2.202.429ubuntu0.12.04.1
released
lucid
ignored