VYPR
Unrated severityNVD Advisory· Published Sep 22, 2015· Updated May 6, 2026

CVE-2015-6682

CVE-2015-6682

Description

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-5584.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Use-after-free in Adobe Flash Player before 18.0.0.241/19.0.0.185 on Windows/OS X and 11.2.202.521 on Linux allows arbitrary code execution.

Vulnerability

A use-after-free vulnerability exists in Adobe Flash Player versions prior to 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X, and prior to 11.2.202.521 on Linux, as well as in Adobe AIR before 19.0.0.190 and related SDKs. The flaw is triggered via unspecified vectors, allowing an attacker to corrupt memory after an object has been freed. This issue is distinct from similar vulnerabilities (CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, CVE-2015-5584) [1][2].

Exploitation

An attacker can exploit this vulnerability by convincing a user to open a specially crafted SWF file, typically through a malicious web page or email attachment. No authentication or special network position is required; the attack is remote and relies on user interaction. The exact sequence of steps is not publicly detailed, but the use-after-free condition is triggered during Flash Player's processing of the crafted content [1][2].

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the affected user. This can lead to full system compromise, including data theft, installation of malware, or denial of service. The vulnerability may also be used to bypass security restrictions or obtain sensitive information [2].

Mitigation

Adobe released fixed versions: Flash Player 18.0.0.241 and 19.0.0.185 for Windows and OS X, 11.2.202.521 for Linux, and AIR 19.0.0.190. Users should update immediately via the vendor's update mechanism or by downloading the latest version. Red Hat and Gentoo have issued advisories directing users to apply the updates [1][2]. No workaround is available.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

36
  • Adobe Inc./Air2 versions
    cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=18.0.0.143
    • (no CPE)range: <19.0.0.190
  • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*range: <=18.0.0.199
    • (no CPE)range: <19.0.0.190
  • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*
    Range: <=18.0.0.180
  • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 24 more
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=13.0.0.289
    • cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:14.0.0.179:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.152:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.167:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.189:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.239:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:15.0.0.246:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.235:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.257:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.287:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:16.0.0.296:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.134:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.169:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.188:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.190:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:17.0.0.191:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.160:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.194:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.203:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.209:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:18.0.0.232:*:*:*:*:*:*:*
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
  • GNU/Flash Playerllm-fuzzy
    Range: <18.0.0.241 / <19.0.0.185 (Windows/OS X), <11.2.202.521 (Linux)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.