May 25, 2022 · Applied Cybernetics Group
CVE-2015-0310 — Adobe Flash Player
Adobe Flash Player ASLR Bypass Vulnerability
- Added to KEV
2022-05-25- Federal due date
2022-06-15- Vendor
- Adobe
- Product
- Flash Player
- EPSS
- 93.2th percentile (score 0.101, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2015-0310
CISA short description
Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
Required action
The impacted product is end-of-life and should be disconnected if still in use.