Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | May 14, 2015 | Apr 14, 2015 |
| Adobe Flash Apsb15 06 | — | Upgrade to Adobe Flash Player version 11.2.202.457 for LinuxUpgrade to Adobe Flash Player version 17.0.0.169 for Mac OS XUpgrade to Adobe Flash Player version 13.0.0.281 for Mac OS XUpgrade to Adobe Flash Player version 13.0.0.281 for WindowsUpgrade to Adobe Flash Player version 17.0.0.169 for Windows | Apr 14, 2015 | Apr 14, 2015 |
| Freebsd | — | Upgrade linux-c6-flashpluginUpgrade linux-f10-flashplugin | Dec 10, 2025 | Apr 17, 2015 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Apr 14, 2015 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-player-kde4Upgrade flash-player | Dec 18, 2015 | Apr 14, 2015 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Apr 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub