CVE-2015-0305

Severity
9.3CRITICAL
EPSS
2.8%
top 13.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 17

Description

Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

NVDadobe/flash_player11.2.202.425+15
NVDadobe/adobe_air15.0.0.356
NVDadobe/adobe_air_sdk15.0.0.356
Ubuntuflashplugin-nonfree< 11.2.202.429ubuntu0.14.04.1

🔴Vulnerability Details

4
GHSA
GHSA-mcf6-5hgw-5w8g: Adobe Flash Player before 132022-05-17
Project0
Attacking ECMAScript Engines with Redefinition - Project Zero2015-08-01
CVEList
CVE-2015-0305: Adobe Flash Player before 132015-01-13
OSV
CVE-2015-0305: Adobe Flash Player before 132015-01-13

📋Vendor Advisories

1
Red Hat
flash-plugin: Multiple code-execution flaws (APSB15-01)2015-01-13

💬Community

1
Bugzilla
CVE-2015-0303 CVE-2015-0306 CVE-2015-0304 CVE-2015-0309 CVE-2015-0305 CVE-2015-0308 flash-plugin: Multiple code-execution flaws (APSB15-01)2015-01-14
CVE-2015-0305 (CRITICAL CVSS 9.3) | Adobe Flash Player before 13.0.0.26 | cvebase.io