CVE-2015-0318
Description
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0321, CVE-2015-0329, and CVE-2015-0330.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Use-after-free in Adobe Flash Player before 13.0.0.269/16.0.0.305/11.2.202.442 allows remote code execution via unspecified vectors.
Vulnerability
A use-after-free vulnerability exists in Adobe Flash Player versions before 13.0.0.269 on Windows and OS X, 16.x before 16.0.0.305, and Linux versions before 11.2.202.442 [1][2][3]. The flaw can be triggered when processing specially crafted SWF content, leading to memory corruption. The specific code path and required user interaction are unspecified in the available references, but it is classified as a critical vulnerability [1][3].
Exploitation
An attacker can exploit this vulnerability by convincing a victim to open a malicious SWF file or visit a web page containing the crafted Flash content. No authentication or special network position is required beyond the ability to deliver the malicious content to the user's browser or application that uses the affected Flash Player [1][2][3]. The exploit likely relies on a use-after-free condition to corrupt memory and gain control of execution flow.
Impact
Successful exploitation allows an attacker to execute arbitrary code on the affected system in the context of the user running Flash Player, or to cause a denial of service via application crash [1][2][3]. The attacker could then install programs, view, change, or delete data, or create new accounts with full user rights. The vulnerability is listed as critical by both Adobe and Microsoft [1].
Mitigation
Adobe released fixed versions: 13.0.0.269 and 16.0.0.305 for Windows and OS X, and 11.2.202.442 for Linux [1][2][3]. Users are advised to update Flash Player immediately via automated update or by downloading the latest version from Adobe's website. On Windows systems, Microsoft released related updates (e.g., MS15-007) for Internet Explorer and Edge [1]. No workaround is available; upgrading to the fixed versions is the only mitigation [3].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
18cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.264
- cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
- (no CPE)range: < 13.0.0.269 on Windows/OS X; < 16.0.0.305 on Windows/OS X; < 11.2.202.442 on Linux
- osv-coords2 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.442-67.1+ 1 more
- (no CPE)range: < 11.2.202.442-67.1
- (no CPE)range: < 11.2.202.442-67.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- helpx.adobe.com/security/products/flash-player/apsb15-04.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-0140.htmlnvd
- secunia.com/advisories/62777nvd
- secunia.com/advisories/62886nvd
- secunia.com/advisories/62895nvd
- security.gentoo.org/glsa/glsa-201502-02.xmlnvd
- www.securityfocus.com/bid/72514nvd
- www.securitytracker.com/id/1031706nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/100702nvd
- technet.microsoft.com/library/security/2755801nvd
News mentions
0No linked articles in our index yet.