CVE-2015-0326 is a critical vulnerability affecting Adobe Flash Player versions prior to 13.0.0.269, 14.x through 16.x before 16.0.0.305 on Windows and OS X, and before 11.2.202.442 on Linux. This flaw allows attackers to cause a denial of service through a NULL pointer dereference, with the potential for other unspecified impacts. With a CVSS score of 10.0, it represents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise potential for confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is listed, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite not being on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.264CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
14.0.0.125CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:* | ||
14.0.0.145CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:* | ||
14.0.0.176CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:* | ||
14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.