VYPR
Unrated severityNVD Advisory· Published Jul 9, 2015· Updated May 6, 2026

CVE-2015-3122

CVE-2015-3122

Description

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-3119, CVE-2015-3120, CVE-2015-3121, and CVE-2015-4433.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A type confusion vulnerability in Adobe Flash Player before patched versions allows remote attackers to execute arbitrary code on affected systems.

Vulnerability

A type confusion vulnerability exists in Adobe Flash Player, affecting versions before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X, and before 11.2.202.481 on Linux. It also affects Adobe AIR before 18.0.0.180, AIR SDK before 18.0.0.180, and AIR SDK & Compiler before 18.0.0.180 [1][2]. The vulnerability is unspecified but is separate from other type confusion issues (CVE-2015-3119, CVE-2015-3120, CVE-2015-3121, CVE-2015-4433).

Exploitation

An attacker can exploit this vulnerability by crafting a malicious SWF file that, when loaded by a victim using an affected Flash Player version, triggers the type confusion. No authentication is required; the attack can be delivered via web pages, email attachments, or other means to lure the user to load the file. The complexity of exploitation is not detailed but remote execution is feasible.

Impact

Successful exploitation allows the attacker to execute arbitrary code in the context of the user running Flash Player. This can lead to full compromise of the affected system, including data theft, installation of malware, or further network propagation. The impact is rated high due to code execution capability.

Mitigation

Adobe released fixed versions on July 8, 2015: Flash Player 18.0.0.203 (Windows/Mac), 13.0.0.302, and 11.2.202.481 (Linux); Adobe AIR 18.0.0.180 [1][2]. Users should update to these versions immediately. Red Hat issued RHSA-2015:1214 for affected Linux platforms [1]. Gentoo GLSA 201507-13 also recommends upgrading [2]. No workaround is available; the only remediation is applying the patches.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

29
  • Adobe Inc./Air2 versions
    cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=18.0.0.144
    • (no CPE)range: before 18.0.0.180
  • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*
    Range: <=18.0.0.144
  • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*range: <=18.0.0.144
    • (no CPE)range: before 18.0.0.180
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.289
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.190:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.160:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.194:*:*:*:*:*:*:*
    • (no CPE)range: before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows/OS X; before 11.2.202.481 on Linux
  • osv-coords2 versions
    < 11.2.202.481-93.1+ 1 more
    • (no CPE)range: < 11.2.202.481-93.1
    • (no CPE)range: < 11.2.202.481-93.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.