Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
Conclusion & alert: CVE-2015-0310 is rated Critical Active Threat (90/100): CVSS High severity, with high exploitation likelihood (EPSS 15.22%, 96th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-05-25) affecting Adobe / Flash Player. a weakness (CWE-200) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Adobe Flash Player ASLR Bypass Vulnerability · CISA KEV detail
: 2022-05-25
: 2022-06-15
: The impacted product is end-of-life and should be disconnected if still in use.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-16 | 15.10% | 15.22% | +0.12% |
| 2 | 2026-06-15 | 10.93% | 15.10% | +4.17% |
| 3 | 2026-06-12 | — | 10.93% | — |
Full EPSS history (29 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
high | CVE-2015-0310: 1 GLSA(s) (201502-02), 1 atom(s) (www-plugins/adobe-flash); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2015-0310 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2015-0310 |
suse
|
high | CVE-2015-0310 severity important: SUSE including 7 source package names (flash-player-11.2.202.438-0.3.1, flash-player-11.2.202.438-27.1, …), 11 product×package rows across 5 product lines (SUSE Linux Enterprise Desktop 11 SP3, SUSE Linux Enterprise Desktop 12, … (5 product lines)): Fixed 11. | https://www.suse.com/security/cve/CVE-2015-0310/ |
ubuntu
|
medium | CVE-2015-0310 medium priority: Ubuntu including 2 source packages (adobe-flashplugin, flashplugin-nonfree), 10 status rows across 5 suites (lucid, precise, trusty, upstream, utopic): released 8, ignored 2. | https://ubuntu.com/security/CVE-2015-0310 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| adobe | flash_player | < 11.2.202.438 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| adobe | flash_player | < 13.0.0.262 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| adobe | flash_player | >= 14.0, < 16.0.0.287 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://helpx.adobe.com/security/products/flash-player/apsb15-02.html | Patch Vendor Advisory |
| http://secunia.com/advisories/62452 | Broken Link |
| http://secunia.com/advisories/62601 | Broken Link |
| http://secunia.com/advisories/62660 | Broken Link |
| http://secunia.com/advisories/62740 | Broken Link |
| http://security.gentoo.org/glsa/glsa-201502-02.xml | Third Party Advisory |
| http://www.securityfocus.com/bid/72261 | Broken Link Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1031609 | Broken Link Third Party Advisory VDB Entry |
| https://github.com/cisagov/vulnrichment/issues/196 | Issue Tracking |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-0310 | US Government Resource |