CVE-2015-3137: Use After Free
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3132, CVE-2015-3136, CVE-2015-4428, CVE-2015-4430, and CVE-2015-5117.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3137?
CVE-2015-3137 is rated as critical due to its potential to allow arbitrary code execution.
How do I fix CVE-2015-3137?
To fix CVE-2015-3137, update Adobe Flash Player to version 13.0.0.302 or later for Windows and OS X, or version 11.2.202.481 or later for Linux.
Which versions of Adobe Flash Player are affected by CVE-2015-3137?
Adobe Flash Player versions prior to 13.0.0.302 and 14.x through 18.x before 18.0.0.203 are affected by CVE-2015-3137.
Are Adobe AIR and Adobe AIR SDK vulnerable to CVE-2015-3137?
Yes, Adobe AIR versions prior to 18.0.0.180 and Adobe AIR SDK/Compiler versions prior to 18.0.0.180 are also vulnerable to CVE-2015-3137.
What operating systems are impacted by CVE-2015-3137?
CVE-2015-3137 affects Adobe Flash Player on Windows, OS X, and Linux platforms.