CVE-2015-0310 is a critical memory address disclosure vulnerability in Adobe Flash Player versions prior to 13.0.0.262, 16.0.0.287, and 11.2.202.438 across Windows, OS X, and Linux platforms. This flaw allows attackers to bypass Address Space Layout Randomization (ASLR) on Windows, significantly increasing the success rate of other exploits, with unspecified impact on other operating systems. Rated with a CVSS score of 7.8 (High), it has a high potential for impact (confidentiality, integrity, availability) and requires user interaction. This vulnerability was actively exploited in the wild in January 2015, as confirmed by its presence on the KEV catalog, and garnered significant community and media attention, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.2.202.438CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 13.0.0.262CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 14.0, < 16.0.0.287CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.