VYPR
Unrated severityNVD Advisory· Published Sep 22, 2015· Updated May 6, 2026

CVE-2015-5587

CVE-2015-5587

Description

Stack-based buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player before 18.0.0.241/19.0.0.185 and AIR before 19.0.0.190 contain a stack-based buffer overflow that allows arbitrary code execution.

Vulnerability

A stack-based buffer overflow exists in Adobe Flash Player versions before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and macOS, and before 11.2.202.521 on Linux. Affected products also include Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190. The vulnerability can be triggered via unspecified vectors, indicating that specially crafted Flash content may cause a buffer overflow on the stack [1][2].

Exploitation

To exploit this vulnerability, an attacker must deliver a malicious SWF file to the target. This can be achieved by hosting the file on a compromised website, injecting it into a legitimate site, or embedding it in an email or ad network. No authentication or prior access is required; user interaction (e.g., visiting a webpage or opening a file) is sufficient to trigger the overflow. The exact exploitation steps are not detailed in the available references, but the stack-based nature suggests a controlled overflow of a stack buffer [2].

Impact

Successful exploitation allows an attacker to execute arbitrary code on the affected system, with the privileges of the user running Flash Player or AIR. This can lead to full compromise of the confidentiality, integrity, and availability of the system, including data theft, installation of malware, or further lateral movement within a network [1][2].

Mitigation

Adobe has released fixes in Flash Player 18.0.0.241/19.0.0.185 (Windows/macOS), 11.2.202.521 (Linux), and AIR 19.0.0.190. Red Hat and Gentoo have also issued updated packages [1][2]. Users should upgrade to these versions immediately. No workaround is known [2].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

34
  • Adobe Inc./Air2 versions
    cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=18.0.0.143
    • (no CPE)range: before 19.0.0.190
  • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*
    Range: <=18.0.0.199
  • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*
    Range: <=18.0.0.180
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 24 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.508
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.190:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.191:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.160:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.194:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.203:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.209:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.232:*:*:*:*:*:*:*
  • Range: before 18.0.0.241 and 19.x before 19.0.0.185 on Windows/OS X, before 11.2.202.521 on Linux

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.