VYPR
Unrated severityNVD Advisory· Published Sep 22, 2015· Updated May 6, 2026

CVE-2015-5584

CVE-2015-5584

Description

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-6682.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Use-after-free in Adobe Flash Player before 18.0.0.241/19.0.0.185 (Windows/OS X) or 11.2.202.521 (Linux) allows arbitrary code execution via unspecified vectors.

Vulnerability

A use-after-free vulnerability exists in Adobe Flash Player versions before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X, and before 11.2.202.521 on Linux, as well as in Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 [1][2]. The flaw is triggered via unspecified vectors and is distinct from several other Adobe Flash Player CVEs [1].

Exploitation

An attacker can exploit this vulnerability by enticing a user to open a specially crafted Flash (SWF) file, typically delivered through a web page or email attachment. No authentication is required; the attacker only needs to convince the victim to interact with the malicious content. The unspecified vectors may include a race condition or improper object cleanup leading to a use-after-free condition [1][2].

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the affected Flash Player process. This can lead to full compromise of the user's system, including data theft, installation of malware, or further propagation within the network [1][2].

Mitigation

Adobe released fixed versions: Flash Player 18.0.0.241 and 19.0.0.185 for Windows/OS X, 11.2.202.521 for Linux, and AIR 19.0.0.190 (including SDK and SDK & Compiler) in September 2015 [1][2]. Red Hat and Gentoo have issued advisories urging users to update immediately [1][2]. No workaround is available; users must apply the updates.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

36
  • Adobe Inc./Air2 versions
    cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=18.0.0.143
    • (no CPE)range: <19.0.0.190
  • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*range: <=18.0.0.199
    • (no CPE)range: <19.0.0.190
  • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*
    Range: <=18.0.0.180
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 25 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.289
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.190:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.191:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.160:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.194:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.203:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.209:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.232:*:*:*:*:*:*:*
    • (no CPE)range: <18.0.0.241, >=19.0.0.0 <19.0.0.185, <11.2.202.521
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.