CVE-2015-8634 is a critical use-after-free vulnerability in Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, and Linux platforms. With a CVSS v3 score of 8.8 (High), it allows unauthenticated remote attackers to execute arbitrary code with low attack complexity, posing a significant threat to confidentiality, integrity, and availability. While not listed in CISA KEV, an ExploitDB entry exists, and the vulnerability garnered notable community discussion and media coverage, indicating its historical significance and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.0.0.268CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
19.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:* | ||
19.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:* | ||
19.0.0.226CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.226:*:*:*:*:*:*:* | ||
19.0.0.245CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.245:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.