CVE-2015-0311 is a critical, unspecified vulnerability in Adobe Flash Player across Windows, OS X, and Linux versions, allowing remote attackers to execute arbitrary code. This vulnerability carries a CVSS score of 9.8, indicating a severe risk with network-based attacks requiring no user interaction, leading to complete compromise of confidentiality, integrity, and availability. It was actively exploited in the wild in January 2015, with public exploit code available in Metasploit and significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.438CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 13.0.0.262CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 14.0.0.125, < 16.0.0.287CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.