CVE-2015-0335 is a critical memory corruption vulnerability in Adobe Flash Player, affecting versions before 13.0.0.277, 14.x through 17.x before 17.0.0.134 on Windows and OS X, and before 11.2.202.451 on Linux. With a CVSS score of 10.0, this vulnerability allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), the vulnerability garnered significant media attention and community discussion at the time of its disclosure. It is not currently listed on CISA's KEV catalog, and its Hot List status is inactive.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.264CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
14.0.0.125CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:* | ||
14.0.0.145CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:* | ||
14.0.0.176CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:* | ||
14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.