CVE-2015-0312 is a critical double free vulnerability in Adobe Flash Player affecting versions before 13.0.0.264, 14.x through 16.x before 16.0.0.296 on Windows and OS X, and before 11.2.202.440 on Linux. This flaw allows unauthenticated attackers to execute arbitrary code remotely with medium attack complexity. With a CVSS score of 9.3 and a FAUCET Risk Score of 82/100, the vulnerability poses a significant risk of complete compromise of confidentiality, integrity, and availability. While no public exploit code is listed for Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.438CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 16.0.0.287CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 16.0.0.287CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 13.0.0.262CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:extended_support:*:*:* | ||
<= 16.0.0.287CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.