CVE-2015-0312
critical
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
9.3
Description
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | - | not-affected | |
| linux-kernel | - | not-affected | |
| windows | - | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | flash_player | {"endIncluding":"11.2.202.438"} | |
| microsoft | internet_explorer | 10 | |
| microsoft | internet_explorer | 11 | |
| adobe | flash_player_desktop_runtime | {"endIncluding":"16.0.0.287"} | |
References
- http://helpx.adobe.com/security/products/flash-player/apsb15-03.html
- http://secunia.com/advisories/62432
- http://secunia.com/advisories/62543
- http://secunia.com/advisories/62660
- http://www.securityfocus.com/bid/72343
- http://www.securitytracker.com/id/1031634
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100394
- https://technet.microsoft.com/library/security/2755801
- http://helpx.adobe.com/security/products/flash-player/apsb15-03.html
- http://secunia.com/advisories/62432
- http://secunia.com/advisories/62543
- http://secunia.com/advisories/62660
- http://www.securityfocus.com/bid/72343
- http://www.securitytracker.com/id/1031634
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100394
- https://technet.microsoft.com/library/security/2755801
CWEs
CWE-415
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.