CVE-2015-8651 KEV
8.8
HIGH · CVSS 3.1 · EPSS 67.7% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-15.
Description
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 67.7% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | yes — remediate by 2022-06-15 |
| Public exploit | none known |
| Published | 2015-12-28 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Adobe Flash Player Integer Overflow Vulnerability |
|---|---|
| Added | 2022-05-25 |
| Due | 2022-06-15 |
| Vendor / product | Adobe / Flash Player |
| Ransomware use | none reported |
Affected (22)
| Vendor | Product |
|---|---|
| adobe | air |
| adobe | air sdk |
| adobe | air sdk \& compiler |
| adobe | flash player |
| apple | iphone os |
| apple | mac os x |
| android | |
| hp | insight control |
| hp | insight control server provisioning |
| hp | matrix operating environment |
| hp | system management homepage |
| hp | systems insight manager |
| hp | version control repository manager |
| linux | linux kernel |
| microsoft | windows |
| opensuse | evergreen |
| opensuse | opensuse |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
| suse | linux enterprise desktop |
| suse | linux enterprise workstation extension |
References
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.html
- http://rhn.redhat.com/errata/RHSA-2015-2697.html
- http://www.securityfocus.com/bid/79705
- http://www.securitytracker.com/id/1034544
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://helpx.adobe.com/security/products/flash-player/apsb16-01.html
- https://security.gentoo.org/glsa/201601-03
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.html
- http://rhn.redhat.com/errata/RHSA-2015-2697.html
- http://www.securityfocus.com/bid/79705
- http://www.securitytracker.com/id/1034544
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388
→ the Explorer · watch your stack · NVD