Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb15 14 | — | Upgrade to Adobe Flash Player version 11.2.202.468 for LinuxUpgrade to Adobe Flash Player version 18.0.0.194 for Mac OS XUpgrade to Adobe Flash Player version 13.0.0.296 for Mac OS XUpgrade to Adobe Flash Player version 18.0.0.194 for WindowsUpgrade to Adobe Flash Player version 13.0.0.296 for Windows | Jun 23, 2015 | Jun 23, 2015 |
| Freebsd | — | Upgrade linux-f10-flashpluginUpgrade linux-c6-flashplugin | Dec 10, 2025 | Jun 24, 2015 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jun 23, 2015 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Jun 23, 2015 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-gnomeUpgrade flash-player-kde4 | Dec 18, 2015 | Jun 23, 2015 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Jun 23, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub