VYPR
Unrated severityNVD Advisory· Published Sep 22, 2015· Updated May 6, 2026

CVE-2015-5570

CVE-2015-5570

Description

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5574, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Use-after-free in Adobe Flash Player's AVSegmentedSource.setSubscribedTags allows remote code execution via crafted SWF.

Vulnerability

A use-after-free vulnerability exists in Adobe Flash Player versions before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X, and before 11.2.202.521 on Linux, as well as in Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 [1][2]. The flaw resides in the handling of the AVSegmentedSource object's setSubscribedTags method, where uninitialized memory can be dereferenced [2].

Exploitation

An attacker must convince a user to visit a malicious web page or open a malicious file that triggers the vulnerable code path [2]. By manipulating the properties of an AVSegmentedSource object and then calling the setSubscribedTags method, the attacker can cause the dereference of uninitialized memory, leading to arbitrary code execution [2].

Impact

Successful exploitation allows an attacker to execute arbitrary code within the context of the current process, potentially leading to full system compromise, including data disclosure, modification, or denial of service [2][3].

Mitigation

Adobe released fixed versions: Flash Player 18.0.0.241 and 19.0.0.185, AIR 19.0.0.190, and Linux Flash Player 11.2.202.521 [1][2]. Red Hat issued RHSA-2015:1814 for affected Red Hat Enterprise Linux packages [1]. Gentoo recommends upgrading to >=www-plugins/adobe-flash-11.2.202.521 [3]. No workaround is available; users should apply the updates immediately.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

36
  • Adobe Inc./Air2 versions
    cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=18.0.0.199
    • (no CPE)range: before 19.0.0.190
  • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*range: <=18.0.0.199
    • (no CPE)range: before 19.0.0.190
  • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*
    Range: <=18.0.0.180
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 24 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.289
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.190:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.191:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.160:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.194:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.203:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.209:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.232:*:*:*:*:*:*:*
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
  • Range: before 18.0.0.241 / 19.0.0.185 (Windows/OS X) and before 11.2.202.521 (Linux)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

14

News mentions

0

No linked articles in our index yet.