Skip to main content

CVE detail

CVE-2015-0336

Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.

CVSS 9.3 · CriticalBuzz score 30.3

Buzz score

Why this CVE is surfacing

Buzz score total 30.3

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 20.8 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
20.8
7 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
7 source links · newest first
  • A group of Georgia Tech researchers have been awarded $100,000 by Facebook for coming up with a novel technique for detecting bad casting vulnerabilities.

    newswww.securityweek.comAug 14, 2015, 5:15 PM
  • Experts at Trend Micro discovered that cyber criminals are exploiting the popular Angler Exploit kit to find and infect PoS systems. The popular Angler Exploit kit is used by criminal crews to find and infect PoS systems, this is the last disconcerting discovery made by the experts at Trend Micro. The security researcher Anthony Joe […]

    newssecurityaffairs.comAug 1, 2015, 8:04 AM
  • An exploit for a Flash Player vulnerability patched recently by Adobe has already been integrated into at least two exploit kits, security firms reported.

    newswww.securityweek.comMar 23, 2015, 4:56 PM
  • Cybercriminals are exploiting newly patched vulnerabilities faster, a sign that users and companies need to improve their software updating habits. Researchers from both Malwarebytes and FireEye reported Thursday that drive-by download attacks using the Nuclear Exploit Kit target a vulnerability that was patched last week in Flash Player. The flaw, which is tracked as CVE-2015-0336, […]

    newswww.csoonline.comMar 20, 2015, 5:33 PM
  • Back in October 2014, we wrote an article about a particular malware campaign we nicknamed ‘EITest’.The actors behind it were using…

    newswww.malwarebytes.comMar 18, 2015, 5:00 PM
  • Adobe released security updates for Adobe Flash Player to fix 11 Critical Vulnerabilities, most of them Remote Code Execution flaws. Adobe has issued a critical update for the Flash Player product that fixes set of 11 critical security vulnerabilities in its software. The update is classified as critical because most of the security flaws could […]

    newssecurityaffairs.comMar 15, 2015, 1:12 PM
  • Adobe has released security updates to patch nearly a dozen serious vulnerabilities affecting the Windows, Mac and Linux versions of Flash Player.

    newswww.securityweek.comMar 13, 2015, 9:02 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence