VYPR
Unrated severityNVD Advisory· Published Feb 6, 2015· Updated May 6, 2026

CVE-2015-0320

CVE-2015-0320

Description

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player before 13.0.0.269 and 16.0.0.305 (Windows/OS X) or 11.2.202.442 (Linux) has a use-after-free vulnerability enabling arbitrary code execution.

Vulnerability

Adobe Flash Player versions prior to 13.0.0.269 and 16.x up to 16.0.0.305 on Windows and OS X, and versions prior to 11.2.202.442 on Linux, contain a use-after-free vulnerability [1][2][3][4]. The bug is triggered via unspecified vectors within the Flash Player engine, leading to memory corruption. Affected versions include Flash Player before 13.0.0.269, 14.x, 15.x, and 16.x before 16.0.0.305 on Windows/OS X, and before 11.2.202.442 on Linux [1][3].

Exploitation

An attacker can exploit this vulnerability by enticing a user to visit a crafted web page or open a specially crafted SWF file [1][2][4]. No special network position beyond delivering content to the target is required; the attack is remote. The exploitation does not require authentication, and the user interaction is limited to normal browsing (e.g., viewing the page containing the malicious Flash content) [1][2].

Impact

Successful exploitation allows the attacker to execute arbitrary code with the privileges of the user running Flash Player [1][2][4]. This can lead to full system compromise, including installation of programs, viewing, changing, or deleting data, and creating new accounts with full user rights. The confidentiality, integrity, and availability of the affected system are all at risk [3][4].

Mitigation

Adobe released fixed versions on February 2, 2015: Flash Player 13.0.0.269, 16.0.0.305, and 11.2.202.442 [1][2][3][4]. Microsoft and Red Hat released corresponding updates for Flash delivered through their products [1][2]. Gentoo users should upgrade to >=www-plugins/adobe-flash-11.2.202.442 [4]. No workarounds are documented; applying the latest updates is the only mitigation [3][4].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

18
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.440
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
  • Range: < 13.0.0.269 or >= 14.0 < 16.0.0.305 (Windows/OS X), < 11.2.202.442 (Linux)
  • osv-coords2 versions
    < 11.2.202.442-67.1+ 1 more
    • (no CPE)range: < 11.2.202.442-67.1
    • (no CPE)range: < 11.2.202.442-67.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

14

News mentions

0

No linked articles in our index yet.