CVE-2015-0328
Description
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-0325 and CVE-2015-0326.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Flash Player before 13.0.0.269, 14–16.x before 16.0.0.305 on Windows/macOS, and before 11.2.202.442 on Linux, contains a NULL pointer dereference that could cause denial of service.
Vulnerability
Adobe Flash Player before version 13.0.0.269, versions 14.x through 16.x before 16.0.0.305 on Windows and macOS, and versions before 11.2.202.442 on Linux, is affected by a NULL pointer dereference vulnerability [2]. The issue can be triggered via unknown vectors, suggesting it may involve crafted Flash content (SWF files) that causes the player to access a NULL memory pointer [2].
Exploitation
An attacker would need to deliver a specially crafted Flash file (SWF) to the target, typically through a web page or email attachment. No special authentication is required; the victim must load the malicious content in a web browser or application that uses the vulnerable Flash Player [2]. The exact trigger is undisclosed, but the NULL pointer dereference occurs when the player processes the malicious input [1].
Impact
Successful exploitation could lead to a denial of service (DoS) via application crash due to the NULL pointer dereference [2]. The description also notes “possibly have unspecified other impact,” which may include arbitrary code execution, though this is not confirmed [2]. The attacker gains no direct privilege escalation, but a crash can disrupt services or user activity [1].
Mitigation
Adobe released fixed versions: 13.0.0.269, 16.0.0.305 on Windows and macOS, and 11.2.202.442 on Linux [2]. Users should update Flash Player to these versions or later. Red Hat released updated packages for Red Hat Enterprise Linux (e.g., flash-plugin-11.2.202.442-1.el6) [2]. Gentoo users can upgrade to >=www-plugins/adobe-flash-11.2.202.442 [3]. Microsoft issued updates for Flash bundled in Internet Explorer and Edge [1]. No workaround is available if patching is not possible [3].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
18cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.264
- cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
- Range: <13.0.0.269 / >=14<16.0.0.305 / <11.2.202.442
- osv-coords2 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.442-67.1+ 1 more
- (no CPE)range: < 11.2.202.442-67.1
- (no CPE)range: < 11.2.202.442-67.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- helpx.adobe.com/security/products/flash-player/apsb15-04.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-0140.htmlnvd
- secunia.com/advisories/62886nvd
- secunia.com/advisories/62895nvd
- security.gentoo.org/glsa/glsa-201502-02.xmlnvd
- www.securityfocus.com/bid/72514nvd
- www.securitytracker.com/id/1031706nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/100713nvd
- technet.microsoft.com/library/security/2755801nvd
News mentions
0No linked articles in our index yet.