CVE-2015-0310
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 01, 2014
- Published Date
- January 23, 2015
- Last Updated
- February 10, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
CVSS Scores
CVSS v3.1
9.8 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
Exploit Status
- Exploited in the Wild
- Yes (added 2022-05-25 00:00:00 UTC) Source
References
http://security.gentoo.org/glsa/glsa-201502-02.xml
http://www.securityfocus.com/bid/72261
http://secunia.com/advisories/62660
http://secunia.com/advisories/62740
http://www.securitytracker.com/id/1031609
http://helpx.adobe.com/security/products/flash-player/apsb15-02.html
http://secunia.com/advisories/62452
http://secunia.com/advisories/62601
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-05-25 00:00:00 UTC |