CVE-2015-7625
Description
Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7626, CVE-2015-7627, CVE-2015-7630, CVE-2015-7633, and CVE-2015-7634.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Flash Player before 18.0.0.252/19.0.0.207 (or 11.2.202.535 on Linux) and AIR before 19.0.0.213 have a memory corruption vulnerability allowing code execution or denial of service via unspecified vectors.
Vulnerability
This is a memory corruption vulnerability in Adobe Flash Player affecting versions before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X, and before 11.2.202.535 on Linux. Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 are also affected. The flaw is triggered via unspecified vectors, indicating that an attacker can craft a malicious SWF file to corrupt memory [1][2][3].
Exploitation
To exploit this vulnerability, an attacker needs to deliver a specially crafted SWF file to the victim. The victim must load a page or open content that uses the malicious SWF file. No additional authentication or special network position beyond standard web delivery is required. The exact exploitation steps are not publicly detailed, but the vulnerability is known to be remotely exploitable [2][3].
Impact
Successful exploitation can allow an attacker to execute arbitrary code with the privileges of the affected process, or cause a denial of service (application crash). This could lead to full system compromise if the Flash process runs with high privileges. The vulnerability also has the potential for information disclosure as part of the memory corruption [2][3].
Mitigation
Adobe released fixed versions: Flash Player 18.0.0.252/19.0.0.207 (Windows/OS X) and 11.2.202.535 (Linux), and Adobe AIR 19.0.0.213. Red Hat provided updated packages (flash-plugin-11.2.202.548) for Red Hat Enterprise Linux 5 Supplementary [2]. Gentoo users can upgrade to www-plugins/adobe-flash-11.2.202.548 [3]. There is no known workaround; users should apply the update promptly [3]. This CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
10cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=19.0.0.190
- (no CPE)range: <19.0.0.213
- cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*Range: <=19.0.0.190
- Range: <18.0.0.252 / <19.0.0.207 / <11.2.202.535
- osv-coords4 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.535-0.20.1+ 3 more
- (no CPE)range: < 11.2.202.535-0.20.1
- (no CPE)range: < 11.2.202.535-0.20.1
- (no CPE)range: < 11.2.202.535-105.1
- (no CPE)range: < 11.2.202.535-105.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- helpx.adobe.com/security/products/flash-player/apsb15-25.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-10/msg00011.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-10/msg00012.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-10/msg00013.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-10/msg00018.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-1893.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-2024.htmlnvd
- www.securityfocus.com/bid/77065nvd
- www.securitytracker.com/id/1033797nvd
- security.gentoo.org/glsa/201511-02nvd
News mentions
0No linked articles in our index yet.