CVE-2015-0323 is a critical heap-based buffer overflow vulnerability in Adobe Flash Player affecting versions before 13.0.0.269, 14.x through 16.x before 16.0.0.305 on Windows and OS X, and before 11.2.202.442 on Linux. With a CVSS score of 10.0, this vulnerability allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity. While not listed in CISA KEV, its high FAUCET Risk Score of 88/100 and EPSS score indicate a significant threat. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage are limited, suggesting it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.264CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
14.0.0.125CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:* | ||
14.0.0.145CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:* | ||
14.0.0.176CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:* | ||
14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.