VYPR
Unrated severityNVD Advisory· Published Sep 22, 2015· Updated May 6, 2026

CVE-2015-5588

CVE-2015-5588

Description

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-6677.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player and AIR memory corruption vulnerability allows remote code execution or denial of service via unspecified vectors.

Vulnerability

Adobe Flash Player versions prior to 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X, and prior to 11.2.202.521 on Linux, along with Adobe AIR before 19.0.0.190 and its SDK before the same version, contain a memory corruption vulnerability triggered via unspecified vectors [1][2]. The exact code path is not disclosed, but the flaw resides in the Flash rendering engine and is reachable when processing crafted SWF content.

Exploitation

An attacker can exploit this vulnerability by convincing a user to open a malicious Flash file or visit a compromised website hosting the crafted content. No authentication or special network position is required beyond delivering the malicious SWF to the target. The unspecified vectors suggest the exploitation does not require additional privileges beyond user interaction [1][2].

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the affected application (browser or AIR runtime) or cause a denial of service via memory corruption. This can lead to full system compromise, data theft, or application crash [1][2].

Mitigation

Adobe released fixed versions on September 21, 2015: Flash Player 18.0.0.241, 19.0.0.185 (Windows/OS X), 11.2.202.521 (Linux), and AIR 19.0.0.190. Red Hat and Gentoo advisories [1][2] recommend upgrading immediately. No workarounds are available; users must apply the vendor-supplied updates.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

35
  • Adobe Inc./Air2 versions
    cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=18.0.0.143
    • (no CPE)range: <19.0.0.190
  • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*
    Range: <=18.0.0.199
  • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*
    Range: <=18.0.0.180
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 24 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.508
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.190:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.191:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.160:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.194:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.203:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.209:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.232:*:*:*:*:*:*:*
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
  • Range: <19.0.0.185

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.