CVE-2015-7663 is a critical use-after-free vulnerability in Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, and Linux platforms. This flaw allows attackers to execute arbitrary code via unspecified vectors, posing a significant risk to systems running affected versions. With a CVSS score of 10.0, it represents a severe threat due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the KEV catalog or public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability garnered significant community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19.0.0.213CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
<= 19.0.0.213CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
<= 19.0.0.213CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* | ||
<= 18.0.0.255CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
19.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.