CVE-2015-8651 is an integer overflow vulnerability in Adobe Flash Player, AIR, and related SDKs across Windows, OS X, and Linux, also impacting products from Apple, Google, HP, Microsoft, and various Linux distributions. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and mentions in exploit kits like RIG, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.0.0.233CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
< 20.0.0.233CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* | ||
< 11.2.202.559CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 20.0.0.233CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
< 18.0.0.324CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.