9.3

CVE-2015-0312

Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
AdobeFlash Player Version <= 11.2.202.438
   LinuxLinux Kernel Version-
AdobeFlash Player Version <= 16.0.0.287
   MicrosoftInternet Explorer Version10
   MicrosoftInternet Explorer Version11 Update-
   MicrosoftWindows 8 Version-
   MicrosoftWindows 8.1 Version-
AdobeFlash Player SwPlatformchrome Version <= 16.0.0.287
   ApplemacOS Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
AdobeFlash Player SwEditionextended_support Version <= 13.0.0.262
   ApplemacOS Version-
   MicrosoftWindows Version-
AdobeFlash Player Desktop Runtime Version <= 16.0.0.287
   ApplemacOS Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.75% 0.889
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-415 Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.