10
CVSSv2

CVE-2015-0310

Published: 23/01/2015 Updated: 13/11/2015
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Flash Player prior to 13.0.0.262 and 14.x up to and including 16.x prior to 16.0.0.287 on Windows and OS X and prior to 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows malicious users to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe flash_player 14.0.0.145

adobe flash_player 14.0.0.125

adobe flash_player 15.0.0.167

adobe flash_player 15.0.0.223

adobe flash_player 14.0.0.176

adobe flash_player 14.0.0.179

adobe flash_player 16.0.0.257

adobe flash_player 16.0.0.235

adobe flash_player 15.0.0.246

adobe flash_player 15.0.0.152

adobe flash_player 15.0.0.239

adobe flash_player 15.0.0.189

Vendor Advisories

Synopsis Critical: flash-plugin security update Type/Severity Security Advisory: Critical Topic An updated Adobe Flash Player package that fixes multiple security issuesis now available for Red Hat Enterprise Linux 5 and 6 SupplementaryRed Hat Product Security has rated this update as having Critical secur ...
Adobe Flash Player before 1300262 and 14x through 16x before 1600287 on Windows and OS X and before 112202438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in ...