AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-0313

CRITICAL · CVSS 9.8 EPSS 95.68% CISA KEV · Actively Exploited Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-02-02 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

Cross-Reference — CISA KEV

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2022-04-13

Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE
CVE-2015-0313
Severity
CRITICAL
CVSS
9.8
EPSS
95.68%
Windows Linux

Original Filing — NVD Description

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.