VYPR
Unrated severityNVD Advisory· Published Mar 13, 2015· Updated May 6, 2026

CVE-2015-0334

CVE-2015-0334

Description

Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0336.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player type confusion vulnerability allows remote code execution; fixed in versions 13.0.0.277, 17.0.0.134, and 11.2.202.451.

Vulnerability

A type confusion vulnerability exists in Adobe Flash Player, affecting versions before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X, and versions before 11.2.202.451 on Linux [1][2]. The issue involves unspecified type confusion that can be triggered by crafted SWF content.

Exploitation

An attacker can exploit this vulnerability by delivering a malicious SWF file to the victim, typically through a web browser or email. No authentication is required, but the victim must open the content in a Flash-enabled application. The exploit does not require any special network position beyond the ability to serve the malicious file.

Impact

Successful exploitation allows arbitrary code execution in the context of the user running Flash Player [1][2]. This can lead to full system compromise, including data theft, installation of malware, or further lateral movement within the network.

Mitigation

Adobe has released fixed versions: Flash Player 13.0.0.277, 17.0.0.134 for Windows/OS X, and 11.2.202.451 for Linux [1][2]. Users should update immediately. No effective workaround exists apart from disabling Flash Player. Both Red Hat [1] and Gentoo [2] advisories confirm the fix.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

19
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.264
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.305:*:*:*:*:*:*:*
    • (no CPE)range: <13.0.0.277 or 14.x-17.x <17.0.0.134 (Windows/OS X); <11.2.202.451 (Linux)
  • osv-coords2 versions
    < 11.2.202.451-77.1+ 1 more
    • (no CPE)range: < 11.2.202.451-77.1
    • (no CPE)range: < 11.2.202.451-77.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.