VYPR
Unrated severityNVD Advisory· Published Aug 14, 2015· Updated May 6, 2026

CVE-2015-5559

CVE-2015-5559

Description

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A use-after-free in Adobe Flash Player before 18.0.0.232 or 11.2.202.508 allows remote attackers to execute arbitrary code.

Vulnerability

A use-after-free vulnerability exists in Adobe Flash Player versions before 18.0.0.232 on Windows and OS X, and before 11.2.202.508 on Linux, as well as in Adobe AIR versions before 18.0.0.199. The flaw is triggered via unspecified vectors, but it is part of a set of vulnerabilities (including CVE-2015-5127, CVE-2015-5130, and others) that are exploited through a crafted SWF file. Attackers can leverage this flaw by convincing a victim to visit a malicious webpage or open a booby-trapped Flash content. [1][2]

Exploitation

An attacker typically exploits this vulnerability by hosting a malicious SWF file or embedding it in a webpage; the victim must access the content through a web browser or a program that uses the affected Flash/AIR runtime. No special privileges are required beyond normal user interaction (clicking a link or opening a document). The use-after-free condition occurs when the Flash player fails to properly manage memory while processing certain ActionScript operations. [2]

Impact

Successful exploitation allows the attacker to execute arbitrary code on the victim's system with the privileges of the affected user. This can lead to complete compromise of confidentiality, integrity, and availability, including the installation of malware, data theft, or further propagation within a network. [1][2]

Mitigation

Adobe released fixed versions: Flash Player 18.0.0.232 (Windows/OS X) and 11.2.202.508 (Linux), and AIR 18.0.0.199. These updates were made available on or around August 11, 2015. Users should update their software immediately; there is no known workaround. [1][2]

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.