← Back to browse · API

CVE-2015-0310

Severity
HIGH
CVSS
7.8
EPSS
0.15217
Risk score
61.53
CISA KEV
Yes
PoC
No
Published
2015-01-23
Modified
2025-11-17
First seen
2026-08-07
Aliases
EUVD-2015-0323, GHSA-3QQ4-W757-RJQM
Products
Adobe:Flash Player, n/a:n/a n/a
Sources
cisa.gov CVE-2015-0310
euvd EUVD-2015-0323

Description

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

References