Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Jan 13, 2015 | Jan 13, 2015 |
| Adobe Flash Apsb15 01 | — | Upgrade to Adobe Flash Player version 13.0.0.260 for WindowsUpgrade to Adobe Flash Player version 16.0.0.257 for WindowsUpgrade to Adobe Flash Player version 13.0.0.260 for Mac OS XUpgrade to Adobe Flash Player version 16.0.0.257 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.429 for Linux | Jan 13, 2015 | Jan 13, 2015 |
| Freebsd | — | Upgrade linux-c6-flashpluginUpgrade linux-f10-flashplugin | Dec 10, 2025 | Jan 22, 2015 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jan 13, 2015 |
| Suse | — | Upgrade flash-player-kde4Upgrade flash-player-gnomeUpgrade flash-player | Dec 18, 2015 | Jan 13, 2015 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Jan 13, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub