Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb15 04 | — | Upgrade to Adobe Flash Player version 16.0.0.305 for WindowsUpgrade to Adobe Flash Player version 16.0.0.305 for Mac OS XUpgrade to Adobe Flash Player version 13.0.0.269 for Mac OS XUpgrade to Adobe Flash Player version 13.0.0.269 for WindowsUpgrade to Adobe Flash Player version 11.2.202.442 for Linux | Feb 5, 2015 | Feb 2, 2015 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-playerUpgrade flash-player-kde4 | Dec 18, 2015 | Feb 2, 2015 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Feb 2, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub