{
  "id": "CVE-2015-3113",
  "url": "https://spydr.io/cve/CVE-2015-3113",
  "published": "2015-06-23T21:59:01.960Z",
  "modified": "2026-06-17T00:25:19.230Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.99812,
  "epss_percentile": 0.99958,
  "exploited": true,
  "kev": {
    "added": "2022-04-13",
    "due": "2022-05-04",
    "action": "The impacted product is end-of-life and should be disconnected if still in use.",
    "ransomware": "Unknown",
    "name": "Adobe Flash Player Heap-Based Buffer Overflow Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2015-3113"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "adobe",
    "opensuse",
    "suse",
    "hp",
    "redhat"
  ],
  "products": [
    "adobe flash player",
    "opensuse evergreen",
    "opensuse",
    "suse linux enterprise desktop",
    "suse linux enterprise workstation extension",
    "hp insight orchestration",
    "hp system management homepage",
    "hp systems insight manager",
    "hp version control agent",
    "hp version control repository manager",
    "hp virtual connect enterprise manager",
    "redhat enterprise linux desktop",
    "redhat enterprise linux eus",
    "redhat enterprise linux server",
    "redhat enterprise linux workstation"
  ],
  "cwes": [
    "CWE-787",
    "CWE-122"
  ],
  "description": "Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00020.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00025.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00002.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=144050155601375&w=2",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1184.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/75371",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securitytracker.com/id/1032696",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1235036",
      "tags": [
        "Issue Tracking"
      ]
    },
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=935701",
      "tags": [
        "Issue Tracking"
      ]
    },
    {
      "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952467",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-14.html",
      "tags": [
        "Broken Link",
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://security.gentoo.org/glsa/201507-13",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.suse.com/security/cve/CVE-2015-3113.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://github.com/cisagov/vulnrichment/issues/196",
      "tags": [
        "Issue Tracking"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3113",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2015-3113",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
