CVE-2015-0307 describes an out-of-bounds read vulnerability in Adobe Flash Player and Adobe AIR across Windows, OS X, Linux, and Android platforms. This flaw allows remote attackers to either extract sensitive information from process memory or trigger a denial of service. With a CVSS score of 8.5, it is considered highly severe due to its network-based attack vector and low attack complexity, potentially leading to partial confidentiality and complete availability impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it is not listed on the KEV catalog, the vulnerability garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* | ||
<= 11.2.202.425CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:android:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk_and_compiler:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.