CVE-2015-0307

CWE-119Buffer Overflow6 documents6 sources
Severity
8.5HIGH
EPSS
5.6%
top 9.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 17

Description

Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:N/A:CExploitability: 10.0 | Impact: 7.8

Affected Packages5 packages

NVDadobe/flash_player11.2.202.425+15
NVDadobe/adobe_air15.0.0.356
NVDadobe/adobe_air_sdk15.0.0.356
Ubuntuflashplugin-nonfree< 11.2.202.429ubuntu0.14.04.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gv3g-rg43-83g9: Adobe Flash Player before 132022-05-17
CVEList
CVE-2015-0307: Adobe Flash Player before 132015-01-13
OSV
CVE-2015-0307: Adobe Flash Player before 132015-01-13

📋Vendor Advisories

1
Red Hat
flash-plugin: Information disclosure via various methods (APSB15-01)2015-01-13

💬Community

1
Bugzilla
CVE-2015-0301 CVE-2015-0302 CVE-2015-0307 flash-plugin: Information disclosure via various methods (APSB15-01)2015-01-14
CVE-2015-0307 (HIGH CVSS 8.5) | Adobe Flash Player before 13.0.0.26 | cvebase.io