CVE-2015-8651
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux,...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 23, 2015
- Published Date
- December 28, 2015
- Last Updated
- February 04, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
CVSS Scores
CVSS v3.1
8.8 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Technical Impact
- total
Exploit Status
- Exploited in the Wild
- Yes (added 2022-05-25 00:00:00 UTC) Source
References
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.html
http://www.securitytracker.com/id/1034544
http://rhn.redhat.com/errata/RHSA-2015-2697.html
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680
https://helpx.adobe.com/security/products/flash-player/apsb16-01.html
http://www.securityfocus.com/bid/79705
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.html
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.html
https://security.gentoo.org/glsa/201601-03
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-05-25 00:00:00 UTC |