CVE-2015-0311
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Flash Player Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 86% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
adobe: flash player; linux: linux kernel; apple: mac os x; microsoft: windows; suse: linux enterprise desktop; suse: linux enterprise workstation extension; microsoft: internet explorer; microsoft: windows 8; microsoft: windows rt; microsoft: windows server 2012; microsoft: windows 10 1507; microsoft: windows 8.1; microsoft: windows rt 8.1; microsoft: edge
קישורים
- http://helpx.adobe.com/security/products/flash-player/apsa15-01.html Vendor Advisory
- https://technet.microsoft.com/library/security/2755801 PatchVendor Advisory
- http://helpx.adobe.com/security/products/flash-player/apsa15-01.html Vendor Advisory
- https://technet.microsoft.com/library/security/2755801 PatchVendor Advisory
- http://helpx.adobe.com/security/products/flash-player/apsb15-03.html Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00027.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00031.html Mailing ListThird Party Advisory
- http://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flas… Third Party Advisory
- http://secunia.com/advisories/62432 Broken Link
- http://secunia.com/advisories/62543 Broken Link