Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | May 14, 2015 | Apr 14, 2015 |
| Adobe Flash Apsb15 06 | — | Upgrade to Adobe Flash Player version 13.0.0.281 for Mac OS XUpgrade to Adobe Flash Player version 17.0.0.169 for Mac OS XUpgrade to Adobe Flash Player version 13.0.0.281 for WindowsUpgrade to Adobe Flash Player version 17.0.0.169 for WindowsUpgrade to Adobe Flash Player version 11.2.202.457 for Linux | Apr 14, 2015 | Apr 14, 2015 |
| Freebsd | — | Upgrade linux-c6-flashpluginUpgrade linux-f10-flashplugin | Dec 10, 2025 | Apr 17, 2015 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Apr 14, 2015 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-kde4Upgrade flash-player-gnome | Dec 18, 2015 | Apr 14, 2015 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Apr 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub