Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb15 18 | — | Upgrade to Adobe Flash Player version 13.0.0.309 for Mac OS XUpgrade to Adobe Flash Player version 18.0.0.209 for Mac OS XUpgrade to Adobe Flash Player version 18.0.0.209 for WindowsUpgrade to Adobe Flash Player version 13.0.0.309 for Windows | Jul 14, 2015 | Jul 14, 2015 |
| Freebsd | — | Upgrade linux-f10-flashpluginUpgrade linux-c6-flashplugin | Dec 10, 2025 | Jul 14, 2015 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jul 14, 2015 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Jul 14, 2015 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-kde4Upgrade flash-player-gnome | Dec 18, 2015 | Jul 14, 2015 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Jul 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub