CVE-2015-0304 is a critical heap-based buffer overflow vulnerability affecting Adobe Flash Player, AIR, AIR SDK, and AIR SDK & Compiler across Windows, OS X, and Linux platforms. With a CVSS score of 10.0, this vulnerability allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity. While not listed on the KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it garnered significant media attention and community discussion at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:android:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk_and_compiler:*:*:*:*:*:*:*:* | ||
<= 13.0.0.259CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.