⚠ Actively exploited
Added to CISA KEV on 2022-05-25. Federal agencies required to patch by 2022-06-15. Required action: The impacted product is end-of-life and should be disconnected if still in use..

CVE-2015-8651

Severity
8.8HIGH
EPSS
89.0%
top 0.48%
CISA KEV
KEV
Added 2022-05-25
Due 2022-06-15
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 28
KEV addedMay 25
KEV dueJun 15
CISA Required Action: The impacted product is end-of-life and should be disconnected if still in use.

Description

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages17 packages

NVDadobe/flash_player19.0.0.18520.0.0.267+2
NVDadobe/air_sdk_\&_compiler< 20.0.0.233
NVDadobe/air< 20.0.0.233
NVDadobe/air_sdk< 20.0.0.233
Ubuntuflashplugin-nonfree< 11.2.202.559ubuntu0.14.04.1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-8p63-f9jh-3gch: Integer overflow in Adobe Flash Player before 182022-05-17
CVEList
CVE-2015-8651: Integer overflow in Adobe Flash Player before 182015-12-28
OSV
CVE-2015-8651: Integer overflow in Adobe Flash Player before 182015-12-28
VulnCheck
Adobe Flash Player Integer Overflow Vulnerability2015

📋Vendor Advisories

2
CISA
Adobe Flash Player Integer Overflow Vulnerability2022-05-25
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-012015-12-28

🕵️Threat Intelligence

3
Qualys
Update: Last Adobe 0-day Patched for the Year | Qualys2015-12-28
Qualys
Update: Last Adobe 0-day Patched for the Year | Qualys2015-12-28
Krebs
Flash Player Patch Fixes 0-Day, 18 Other Flaws &#8211; Krebs on Security2015-12-01

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-012015-12-29
CVE-2015-8651 (HIGH CVSS 8.8) | Integer overflow in Adobe Flash Pla | cvebase.io