peter bassill · operator
$ cve CVE-2015-8651 JSON

CVE-2015-8651 KEV

8.8
HIGH · CVSS 3.1 · EPSS 67.7% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-15.

Description

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS67.7% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-190
On CISA KEVyes — remediate by 2022-06-15
Public exploitnone known
Published2015-12-28
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Integer Overflow Vulnerability
Added2022-05-25
Due2022-06-15
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (22)

VendorProduct
adobeair
adobeair sdk
adobeair sdk \& compiler
adobeflash player
appleiphone os
applemac os x
googleandroid
hpinsight control
hpinsight control server provisioning
hpmatrix operating environment
hpsystem management homepage
hpsystems insight manager
hpversion control repository manager
linuxlinux kernel
microsoftwindows
opensuseevergreen
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise workstation extension

References

→ the Explorer  ·  watch your stack  ·  NVD