CVE-2015-0313: Adobe Flash Player Use-After-Free Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 95.3% chance of exploitation in the next 30 days.

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

Affected products

  • Adobe Flash Player: before 11.2.202.442 (fixed in 11.2.202.442); before 13.0.0.269 (fixed in 13.0.0.269); from 14.0.0.125, before 16.0.0.305 (fixed in 16.0.0.305)
  • Microsoft Edge: affected versions not specified
  • Microsoft Internet Explorer: version 10 only; version 11 only
  • Opensuse Evergreen: version 11.4 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Suse Linux Enterprise Desktop: version 11 only; version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2015-02-02. Last modified 2026-06-17.