CVE-2015-8635 is a critical use-after-free vulnerability in Adobe Flash Player, AIR, AIR SDK, and AIR SDK & Compiler across Windows, OS X, and Linux platforms. This flaw allows unauthenticated attackers to execute arbitrary code remotely through user interaction. With a CVSS v3 score of 8.8 (High) and a FAUCET Risk Score of 98/100, the vulnerability poses a significant risk of complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit code is publicly available on ExploitDB, and it has garnered substantial community discussion and media coverage, including reports of an emergency patch for a Flash zero-day under attack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.554CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* | ||
<= 18.0.0.268CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.