CVE-2015-0359
Description
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Flash Player before 13.0.0.281 and 17.x before 17.0.0.169 on Windows/OS X, or before 11.2.202.457 on Linux, has a double free vulnerability leading to arbitrary code execution.
Vulnerability
A double-free vulnerability exists in Adobe Flash Player versions before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X, and before 11.2.202.457 on Linux [1][2]. The flaw is triggered via unspecified vectors, indicating that processing a specially crafted SWF file can cause the player to free the same memory region twice [1]. This vulnerability is distinct from CVE-2015-0346.
Exploitation
An attacker would need to deliver a malicious SWF file to the victim, for example through a compromised website or via a crafted advertisement. No special authentication or network position beyond the ability to serve the SWF is required. The victim must visit the malicious page or open the file in a browser or application that uses the vulnerable Flash Player. The exploit sequence involves triggering the double-free condition during Flash Player's handling of the SWF content.
Impact
Successful exploitation allows arbitrary code execution in the context of the affected Flash Player process [1][2]. An attacker could potentially install programs, view, change, or delete data, or create new accounts with full user rights. The impact is limited only by the privileges of the account under which the Flash Player runs.
Mitigation
Adobe released fixed versions: Flash Player 13.0.0.281 and 17.0.0.169 for Windows and OS X, and 11.2.202.457 for Linux [1]. Users should upgrade to these versions or later. Red Hat and Gentoo have released updated packages (e.g., RHSA-2015:0813 and GLSA 201504-07) [2]. If upgrading is not immediately possible, the only known workaround is to disable or remove the Flash Player plugin.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
19cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.264
- cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
- (no CPE)range: <17.0.0.169
- osv-coords2 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.457-80.1+ 1 more
- (no CPE)range: < 11.2.202.457-80.1
- (no CPE)range: < 11.2.202.457-80.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- helpx.adobe.com/security/products/flash-player/apsb15-06.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-0813.htmlnvd
- www.securityfocus.com/bid/74067nvd
- www.securitytracker.com/id/1032105nvd
- security.gentoo.org/glsa/201504-07nvd
News mentions
0No linked articles in our index yet.