Back

CVE-2015-0313

CRITICAL CISA KEV

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

Published: Feb 2, 2015 Modified: Apr 21, 2026
CWE-416 CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (12)

Vendor Product Version
adobe flash_player * < 11.2.202.442
adobe flash_player * < 13.0.0.269
adobe flash_player * ≥ 14.0.0.125 < 16.0.0.305
opensuse evergreen 11.4
opensuse opensuse 13.1
opensuse opensuse 13.2
suse linux_enterprise_desktop 11
suse linux_enterprise_desktop 12
suse linux_enterprise_workstation_extension 12
microsoft internet_explorer 10
microsoft internet_explorer 11
microsoft edge -

GitHub Security Advisory GHSA-fg66-4vpm-36cx

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 92.54%

Top 0% most likely to be exploited

Threat Score 97 / 100

CISA Known Exploited

Date Added: 2022-04-13
Due Date: 2022-05-04
Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

Data Sources

NVD CISA KEV EPSS GitHub