CVE-2015-0356: Critical severity macromedia flash player vulnerability
Published Apr 14, 2015
·Updated
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion."
Affected Software
20 affected components
Adobe Flash Player<=11.2.202.451
Linux Linux kernel
Adobe Flash Player<=13.0.0.264
Adobe Flash Player=14.0.0.125
Adobe Flash Player=14.0.0.145
Adobe Flash Player=14.0.0.176
Adobe Flash Player=14.0.0.179
Adobe Flash Player=15.0.0.152
Adobe Flash Player=15.0.0.167
Adobe Flash Player=15.0.0.189
Adobe Flash Player=15.0.0.223
Adobe Flash Player=15.0.0.239
Adobe Flash Player=15.0.0.246
Adobe Flash Player=16.0.0.235
Adobe Flash Player=16.0.0.257
Adobe Flash Player=16.0.0.287
Adobe Flash Player=16.0.0.296
Adobe Flash Player=17.0.0.134
Apple iOS and macOS
Microsoft Windows
Remediation
Event History
Apr 14, 2015
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0356?
CVE-2015-0356 has a critical severity level as it allows attackers to execute arbitrary code.
2
How do I fix CVE-2015-0356?
To fix CVE-2015-0356, update Adobe Flash Player to the latest version beyond 17.0.0.169.
3
Which versions are affected by CVE-2015-0356?
CVE-2015-0356 affects Adobe Flash Player versions prior to 13.0.0.281 and 14.x through 17.x before 17.0.0.169.
4
What platforms are impacted by CVE-2015-0356?
CVE-2015-0356 impacts Adobe Flash Player on Windows, OS X, and Linux platforms.
5
What type of vulnerability is CVE-2015-0356?
CVE-2015-0356 is classified as a type confusion vulnerability allowing unrestricted code execution.