CVE-2015-7626 is a critical memory corruption vulnerability affecting Adobe Flash Player across Windows, OS X, and Linux, as well as Adobe AIR and its SDKs. This flaw allows unauthenticated remote attackers to execute arbitrary code or trigger a denial of service through unspecified vectors. With a CVSS score of 10.0, it represents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While the vulnerability is not listed on the KEV catalog and lacks public exploit intelligence (Metasploit, Nuclei, ExploitDB), its high FAUCET Risk Score of 90/100 indicates significant potential danger. There is no evidence of active exploitation, nor has it garnered community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19.0.0.190CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
<= 11.2.202.521CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 19.0.0.190CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
<= 19.0.0.190CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* | ||
<= 19.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.