CVE-2015-0320
Description
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Flash Player before 13.0.0.269 and 16.0.0.305 (Windows/OS X) or 11.2.202.442 (Linux) has a use-after-free vulnerability enabling arbitrary code execution.
Vulnerability
Adobe Flash Player versions prior to 13.0.0.269 and 16.x up to 16.0.0.305 on Windows and OS X, and versions prior to 11.2.202.442 on Linux, contain a use-after-free vulnerability [1][2][3][4]. The bug is triggered via unspecified vectors within the Flash Player engine, leading to memory corruption. Affected versions include Flash Player before 13.0.0.269, 14.x, 15.x, and 16.x before 16.0.0.305 on Windows/OS X, and before 11.2.202.442 on Linux [1][3].
Exploitation
An attacker can exploit this vulnerability by enticing a user to visit a crafted web page or open a specially crafted SWF file [1][2][4]. No special network position beyond delivering content to the target is required; the attack is remote. The exploitation does not require authentication, and the user interaction is limited to normal browsing (e.g., viewing the page containing the malicious Flash content) [1][2].
Impact
Successful exploitation allows the attacker to execute arbitrary code with the privileges of the user running Flash Player [1][2][4]. This can lead to full system compromise, including installation of programs, viewing, changing, or deleting data, and creating new accounts with full user rights. The confidentiality, integrity, and availability of the affected system are all at risk [3][4].
Mitigation
Adobe released fixed versions on February 2, 2015: Flash Player 13.0.0.269, 16.0.0.305, and 11.2.202.442 [1][2][3][4]. Microsoft and Red Hat released corresponding updates for Flash delivered through their products [1][2]. Gentoo users should upgrade to >=www-plugins/adobe-flash-11.2.202.442 [4]. No workarounds are documented; applying the latest updates is the only mitigation [3][4].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
18cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.440
- cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
- Range: < 13.0.0.269 or >= 14.0 < 16.0.0.305 (Windows/OS X), < 11.2.202.442 (Linux)
- osv-coords2 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.442-67.1+ 1 more
- (no CPE)range: < 11.2.202.442-67.1
- (no CPE)range: < 11.2.202.442-67.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- helpx.adobe.com/security/products/flash-player/apsb15-04.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-0140.htmlnvd
- secunia.com/advisories/62777nvd
- secunia.com/advisories/62886nvd
- secunia.com/advisories/62895nvd
- security.gentoo.org/glsa/glsa-201502-02.xmlnvd
- www.securityfocus.com/bid/72514nvd
- www.securitytracker.com/id/1031706nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/100698nvd
- technet.microsoft.com/library/security/2755801nvd
News mentions
0No linked articles in our index yet.