CVE-2015-0331Adobe Flash Player vulnerability

7 documents6 sources
Severity
10.0CRITICALNVD
OSV9.8
EPSS
9.4%
top 7.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 21
Latest updateMay 17

Description

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDadobe/flash_player13.0.0.264+15

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rr27-273m-v696: Use-after-free vulnerability in Adobe Flash Player before 132022-05-17
OSV
CVE-2015-0331: Use-after-free vulnerability in Adobe Flash Player before 132015-02-21

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution flaws (APSB15-04)2015-02-04

🕵️Threat Intelligence

2
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities2015-03-17
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities2015-03-17

💬Community

1
Bugzilla
flash-plugin: multiple code execution flaws (APSB15-04)2015-02-06