← Back to CVE List
Vulnerability Intelligence Report
Adobe Flash Player ASLR Bypass Vulnerability

CVE-2015-0310

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:15.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-200 ↗CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected Products & Versions

Vendor Product Affected Versions
adobe flash_player all
linux linux_kernel all
apple mac_os_x all
microsoft windows all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
15.217%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2014-12-01T00:00:00
Published2015-01-23T21:00:00
Patch Date2015-01-22
Last Updated2025-11-17T20:10:36

LINK COPIED TO CLIPBOARD