Skip to main content

CVE-2015-0310

7.8
HIGHCVSS v3.1 Base Score
10.11%
LOW RiskEPSS (93rd percentile)
KEV
NVD-CWE-noinfo

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

Published: 1/23/2015
Modified: 4/21/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Adobe Flash Player ASLR Bypass Vulnerability

Vendor / Product:

Adobe Flash Player

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

Due Date: 6/15/2022(OVERDUE)
Added to KEV:

5/25/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2015-0310

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

10

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

10.11%LOW Exploitation Risk
93rd percentile

This vulnerability has a 10.11% probability of being exploited in the next 30 days, ranking higher than 93% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities