CVE-2015-0311
adobe flash player, suse linux enterprise desktop, suse linux enterprise workstation extension
Published 23 Jan 2015 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 13 Apr 2022, with a remediation deadline of 4 May 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
References
- helpx.adobe.com/security/products/flash-player/apsa15-01.html · Vendor Advisory
- helpx.adobe.com/security/products/flash-player/apsb15-03.html · Broken Link
- lists.opensuse.org/opensuse-security-announce/2015-01/msg00027.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2015-01/msg00031.html · Mailing List, Third Party Advisory
- malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.html · Third Party Advisory
- secunia.com/advisories/62432 · Broken Link
- secunia.com/advisories/62543 · Broken Link
- secunia.com/advisories/62650 · Broken Link
- secunia.com/advisories/62660 · Broken Link
- secunia.com/advisories/62740 · Broken Link
- security.gentoo.org/glsa/glsa-201502-02.xml · Third Party Advisory
- www.securityfocus.com/bid/72283 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1031597 · Broken Link, Third Party Advisory, VDB Entry
- technet.microsoft.com/library/security/2755801 · Patch, Vendor Advisory
- github.com/cisagov/vulnrichment/issues/196 · Issue Tracking
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-0311 · US Government Resource