CVE-2015-0334 is a critical type confusion vulnerability in Adobe Flash Player, affecting versions before 13.0.0.277, 14.x through 17.x before 17.0.0.134 on Windows and OS X, and before 11.2.202.451 on Linux. This flaw allows remote attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability. While the vulnerability has a high CVSS score of 9.3 and a FAUCET Risk Score of 82/100, there is no indication of active exploitation (KEV: No), and public exploit intelligence (Metasploit, Nuclei, ExploitDB) is unavailable. Despite limited community discussion and media coverage, its severity warrants prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.264CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
14.0.0.125CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:* | ||
14.0.0.145CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:* | ||
14.0.0.176CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:* | ||
14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.