Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2015-7645 Details
Description
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025Exploitation: ActiveAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Adobe Flash Player Arbitrary Code Execution Vulnerability | Mar 3, 2022 | Mar 24, 2022 | The impacted product is end-of-life and should be disconnected if still in use. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe flash player | >= 18.0.0.160, <= 18.0.0.252 19.0.0.185 19.0.0.207 <= 11.2.202.535 |
CPE
Remediation
| |
| apple mac os x | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| opensuse evergreen | 11.4 |
CPE
Remediation
| |
| opensuse opensuse | 13.1 13.2 |
CPE
Remediation
| |
| suse linux enterprise desktop | 11 sp3 11 sp4 12 - |
CPE
Remediation
| |
| suse linux enterprise workstation extension | 12 - |
CPE
Remediation
| |
| redhat enterprise linux desktop | 5.0 6.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 6.7 |
CPE
Remediation
| |
| redhat enterprise linux server | 5.0 6.0 |
CPE
Remediation
| |
| redhat enterprise linux server from rhui | 5.0 6.0 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 5.0 6.0 |
CPE
Remediation
| |
Change History
20 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 14, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 16, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 1, 2017 | CVE Modified | [email protected] |
| Dec 24, 2016 | CVE Modified | [email protected] |
| Dec 8, 2016 | CVE Modified | [email protected] |
| Dec 7, 2016 | CVE Modified | [email protected] |
| Nov 28, 2016 | CVE Modified | [email protected] |
| Oct 20, 2015 | CVE Modified | [email protected] |
| Oct 16, 2015 | Modified Analysis | [email protected] |
| Oct 16, 2015 | Initial Analysis | [email protected] |