VYPR
Unrated severityNVD Advisory· Published Feb 6, 2015· Updated May 6, 2026

CVE-2015-0328

CVE-2015-0328

Description

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-0325 and CVE-2015-0326.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player before 13.0.0.269, 14–16.x before 16.0.0.305 on Windows/macOS, and before 11.2.202.442 on Linux, contains a NULL pointer dereference that could cause denial of service.

Vulnerability

Adobe Flash Player before version 13.0.0.269, versions 14.x through 16.x before 16.0.0.305 on Windows and macOS, and versions before 11.2.202.442 on Linux, is affected by a NULL pointer dereference vulnerability [2]. The issue can be triggered via unknown vectors, suggesting it may involve crafted Flash content (SWF files) that causes the player to access a NULL memory pointer [2].

Exploitation

An attacker would need to deliver a specially crafted Flash file (SWF) to the target, typically through a web page or email attachment. No special authentication is required; the victim must load the malicious content in a web browser or application that uses the vulnerable Flash Player [2]. The exact trigger is undisclosed, but the NULL pointer dereference occurs when the player processes the malicious input [1].

Impact

Successful exploitation could lead to a denial of service (DoS) via application crash due to the NULL pointer dereference [2]. The description also notes “possibly have unspecified other impact,” which may include arbitrary code execution, though this is not confirmed [2]. The attacker gains no direct privilege escalation, but a crash can disrupt services or user activity [1].

Mitigation

Adobe released fixed versions: 13.0.0.269, 16.0.0.305 on Windows and macOS, and 11.2.202.442 on Linux [2]. Users should update Flash Player to these versions or later. Red Hat released updated packages for Red Hat Enterprise Linux (e.g., flash-plugin-11.2.202.442-1.el6) [2]. Gentoo users can upgrade to >=www-plugins/adobe-flash-11.2.202.442 [3]. Microsoft issued updates for Flash bundled in Internet Explorer and Edge [1]. No workaround is available if patching is not possible [3].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

18
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.264
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
  • GNU/Flash Playerllm-fuzzy
    Range: <13.0.0.269 / >=14<16.0.0.305 / <11.2.202.442
  • osv-coords2 versions
    < 11.2.202.442-67.1+ 1 more
    • (no CPE)range: < 11.2.202.442-67.1
    • (no CPE)range: < 11.2.202.442-67.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.