CVE-2015-3113: Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 99.8% chance of exploitation in the next 30 days.

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

Affected products

  • Adobe Flash Player: before 13.0.0.296 (fixed in 13.0.0.296); from 14.0.0.125, before 18.0.0.194 (fixed in 18.0.0.194); before 11.2.202.468 (fixed in 11.2.202.468)
  • HP Insight Orchestration: before 7.5.0 (fixed in 7.5.0)
  • HP System Management Homepage: before 7.5.0 (fixed in 7.5.0)
  • HP Systems Insight Manager: before 7.5 (fixed in 7.5)
  • HP Version Control Agent: before 7.5.0 (fixed in 7.5.0)
  • HP Version Control Repository Manager: before 7.5.0 (fixed in 7.5.0); version 7.6 only
  • HP Virtual Connect Enterprise Manager: before 7.5.0 (fixed in 7.5.0)
  • Opensuse Evergreen: version 11.4 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.6 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2015-06-23. Last modified 2026-06-17.