CVE-2015-0306

Severity
10.0CRITICAL
EPSS
11.3%
top 6.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 17

Description

Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0303.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages5 packages

NVDadobe/flash_player13.0.0.259+15
NVDadobe/adobe_air15.0.0.356
NVDadobe/adobe_air_sdk15.0.0.356
Ubuntuflashplugin-nonfree< 11.2.202.429ubuntu0.14.04.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rphv-gx2h-wqmr: Adobe Flash Player before 132022-05-17
OSV
CVE-2015-0306: Adobe Flash Player before 132015-01-13
CVEList
CVE-2015-0306: Adobe Flash Player before 132015-01-13

📋Vendor Advisories

2
Red Hat
flash-plugin: Multiple code-execution flaws (APSB15-01)2015-01-13
Red Hat
flash-plugin: Multiple code-execution flaws (APSB15-01)2015-01-13

💬Community

1
Bugzilla
CVE-2015-0303 CVE-2015-0306 CVE-2015-0304 CVE-2015-0309 CVE-2015-0305 CVE-2015-0308 flash-plugin: Multiple code-execution flaws (APSB15-01)2015-01-14
CVE-2015-0306 (CRITICAL CVSS 10) | Adobe Flash Player before 13.0.0.26 | cvebase.io