First published: Wed Jan 28 2015(Updated: )
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=11.2.202.438 | |
Linux Kernel | ||
Macromedia Flash Player | <=16.0.0.287 | |
Internet Explorer | =10 | |
Internet Explorer | =11 | |
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Macromedia Flash Player | <=16.0.0.287 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Macromedia Flash Player | <=13.0.0.262 | |
Adobe Flash Player | <=16.0.0.287 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0312 is a critical vulnerability that can allow attackers to execute arbitrary code.
To fix CVE-2015-0312, update Adobe Flash Player to version 13.0.0.264 or later for supported versions.
CVE-2015-0312 affects Adobe Flash Player versions prior to 13.0.0.264 and 14.x through 16.x before 16.0.0.296.
Yes, CVE-2015-0312 can be exploited on Linux systems running vulnerable versions of Adobe Flash Player.
CVE-2015-0312 can lead to arbitrary code execution, potentially compromising the affected system.