CVE-2015-3131
Description
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3132, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4430, and CVE-2015-5117.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Flash Player before 13.0.0.302/18.0.0.203 and AIR before 18.0.0.180 contain a use-after-free that allows arbitrary code execution.
Vulnerability
A use-after-free vulnerability exists in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X, before 11.2.202.481 on Linux, and in Adobe AIR before 18.0.0.180, AIR SDK before 18.0.0.180, and AIR SDK & Compiler before 18.0.0.180 [1], [2]. The flaw allows attackers to execute arbitrary code via unspecified vectors [1]. This vulnerability is distinct from several other CVEs disclosed in the same update [1].
Exploitation
An attacker can exploit this vulnerability without authentication by delivering a crafted SWF file (or other Flash content) to a victim, typically through web-based delivery [1], [2]. The user must open the malicious content in a vulnerable Flash Player instance. The exact attack vector is not disclosed in the available references, but the issue is triggered when the player attempts to access an object that has already been freed [1], [2].
Impact
Successful exploitation allows the attacker to execute arbitrary code in the context of the user running Flash Player, potentially leading to full compromise of the affected system [1], [2]. The attacker can also cause denial of service, obtain sensitive information, or bypass security restrictions [2].
Mitigation
Adobe released updates to fix the vulnerability: Flash Player 13.0.0.302 and 18.0.0.203 (Windows/Mac), 11.2.202.481 (Linux), and AIR 18.0.0.180 (and corresponding SDK versions) [1], [2]. Red Hat distributed updated packages in RHSA-2015:1214 for RHEL [1], and Gentoo recommended upgrading to www-plugins/adobe-flash-11.2.202.481 [2]. No workaround is available [2]. Users should apply the update immediately.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
29cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=18.0.0.144
- (no CPE)range: <=18.0.0.180
cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*range: <=18.0.0.144
- (no CPE)range: <=18.0.0.180
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.468
- cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:17.0.0.190:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:18.0.0.160:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:18.0.0.194:*:*:*:*:*:*:*
- (no CPE)range: <=18.0.0.203 (Windows/OS X) and <=11.2.202.481 (Linux)
- osv-coords2 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.481-93.1+ 1 more
- (no CPE)range: < 11.2.202.481-93.1
- (no CPE)range: < 11.2.202.481-93.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- helpx.adobe.com/security/products/flash-player/apsb15-16.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00017.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00018.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-1214.htmlnvd
- www.securityfocus.com/bid/75590nvd
- www.securitytracker.com/id/1032810nvd
- security.gentoo.org/glsa/201507-13nvd
News mentions
0No linked articles in our index yet.