CVE-2015-0317
Description
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0319.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Flash Player before 13.0.0.269/16.0.0.305 (Windows/OS X) and 11.2.202.442 (Linux) contains a type confusion vulnerability allowing arbitrary code execution.
Vulnerability
Adobe Flash Player versions prior to 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X, and versions before 11.2.202.442 on Linux, are affected by an unspecified type confusion vulnerability [2][3]. This memory corruption flaw occurs when the software mishandles object types, potentially triggered by a crafted SWF file. No special configuration is required; the vulnerability is reachable through any content that invokes the Flash Player plugin or standalone player.
Exploitation
An attacker can exploit this vulnerability by hosting a malicious SWF file on a website or delivering it via email or other means. The victim must open the file or visit the malicious page using a vulnerable Flash Player instance. No authentication or prior access is needed. The type confusion leads to memory corruption, which the attacker can leverage to execute arbitrary code in the context of the user running Flash Player [2][3].
Impact
Successful exploitation grants the attacker arbitrary code execution at the privilege level of the affected user. This can result in full system compromise, including data theft, installation of malware, or further lateral movement within a network. The impact is limited to the user's permissions, but combined with other vulnerabilities could lead to elevated privileges [2][3].
Mitigation
Adobe released fixed versions: 13.0.0.269, 16.0.0.305, and 11.2.202.442 in February 2015. Microsoft provided updates via Security Advisory 2755801 for Flash Player in Internet Explorer and Edge [1]. Red Hat issued RHSA-2015-0140 for affected Linux distributions [2], and Gentoo published GLSA 201502-02 recommending upgrade to the patched version [3]. No workaround is available; users should apply the latest updates immediately.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
18cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.440
- cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
- (no CPE)range: before 13.0.0.269 and 14.x through 16.x before 16.0.0.305
- osv-coords2 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.442-67.1+ 1 more
- (no CPE)range: < 11.2.202.442-67.1
- (no CPE)range: < 11.2.202.442-67.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- helpx.adobe.com/security/products/flash-player/apsb15-04.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-0140.htmlnvd
- secunia.com/advisories/62777nvd
- secunia.com/advisories/62886nvd
- secunia.com/advisories/62895nvd
- security.gentoo.org/glsa/glsa-201502-02.xmlnvd
- www.securityfocus.com/bid/72514nvd
- www.securitytracker.com/id/1031706nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/100706nvd
- technet.microsoft.com/library/security/2755801nvd
News mentions
0No linked articles in our index yet.