CVE-2015-8459 is a critical memory corruption vulnerability affecting multiple versions of Adobe Flash Player, Adobe AIR, and related SDKs across Windows, OS X, and Linux platforms. With a CVSS score of 10.0, this vulnerability allows unauthenticated attackers to execute arbitrary code or cause a denial of service over the network with high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, media coverage and community discussion indicate active exploitation and significant attention at the time of its discovery, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* | ||
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
<= 11.2.202.554CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 18.0.0.268CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.