VYPR
Unrated severityNVD Advisory· Published Feb 6, 2015· Updated May 6, 2026

CVE-2015-0317

CVE-2015-0317

Description

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0319.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player before 13.0.0.269/16.0.0.305 (Windows/OS X) and 11.2.202.442 (Linux) contains a type confusion vulnerability allowing arbitrary code execution.

Vulnerability

Adobe Flash Player versions prior to 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X, and versions before 11.2.202.442 on Linux, are affected by an unspecified type confusion vulnerability [2][3]. This memory corruption flaw occurs when the software mishandles object types, potentially triggered by a crafted SWF file. No special configuration is required; the vulnerability is reachable through any content that invokes the Flash Player plugin or standalone player.

Exploitation

An attacker can exploit this vulnerability by hosting a malicious SWF file on a website or delivering it via email or other means. The victim must open the file or visit the malicious page using a vulnerable Flash Player instance. No authentication or prior access is needed. The type confusion leads to memory corruption, which the attacker can leverage to execute arbitrary code in the context of the user running Flash Player [2][3].

Impact

Successful exploitation grants the attacker arbitrary code execution at the privilege level of the affected user. This can result in full system compromise, including data theft, installation of malware, or further lateral movement within a network. The impact is limited to the user's permissions, but combined with other vulnerabilities could lead to elevated privileges [2][3].

Mitigation

Adobe released fixed versions: 13.0.0.269, 16.0.0.305, and 11.2.202.442 in February 2015. Microsoft provided updates via Security Advisory 2755801 for Flash Player in Internet Explorer and Edge [1]. Red Hat issued RHSA-2015-0140 for affected Linux distributions [2], and Gentoo published GLSA 201502-02 recommending upgrade to the patched version [3]. No workaround is available; users should apply the latest updates immediately.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

18
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.440
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • (no CPE)range: before 13.0.0.269 and 14.x through 16.x before 16.0.0.305
  • osv-coords2 versions
    < 11.2.202.442-67.1+ 1 more
    • (no CPE)range: < 11.2.202.442-67.1
    • (no CPE)range: < 11.2.202.442-67.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

14

News mentions

0

No linked articles in our index yet.