CVE-2015-3113: Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 99.8% chance of exploitation in the next 30 days.
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
Affected products
- Adobe Flash Player: before 13.0.0.296 (fixed in 13.0.0.296); from 14.0.0.125, before 18.0.0.194 (fixed in 18.0.0.194); before 11.2.202.468 (fixed in 11.2.202.468)
- HP Insight Orchestration: before 7.5.0 (fixed in 7.5.0)
- HP System Management Homepage: before 7.5.0 (fixed in 7.5.0)
- HP Systems Insight Manager: before 7.5 (fixed in 7.5)
- HP Version Control Agent: before 7.5.0 (fixed in 7.5.0)
- HP Version Control Repository Manager: before 7.5.0 (fixed in 7.5.0); version 7.6 only
- HP Virtual Connect Enterprise Manager: before 7.5.0 (fixed in 7.5.0)
- Opensuse Evergreen: version 11.4 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Eus: version 6.6 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2015-06-23. Last modified 2026-06-17.