CVE-2015-0313: Adobe Flash Player Use-After-Free Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 95.3% chance of exploitation in the next 30 days.
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Affected products
- Adobe Flash Player: before 11.2.202.442 (fixed in 11.2.202.442); before 13.0.0.269 (fixed in 13.0.0.269); from 14.0.0.125, before 16.0.0.305 (fixed in 16.0.0.305)
- Microsoft Edge: affected versions not specified
- Microsoft Internet Explorer: version 10 only; version 11 only
- Opensuse Evergreen: version 11.4 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Suse Linux Enterprise Desktop: version 11 only; version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2015-02-02. Last modified 2026-06-17.