CVE-2015-8644 is a critical type confusion vulnerability in Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, and Linux platforms. This flaw allows remote attackers to execute arbitrary code on affected systems. With a CVSS v3 score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, an ExploitDB entry exists for a "SimpleButton Creation Type Confusion," and it garnered notable community discussion and media coverage at the time of its disclosure, including reports of an emergency patch addressing a Flash zero-day under attack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.0.0.268CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
19.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:* | ||
19.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:* | ||
19.0.0.226CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.226:*:*:*:*:*:*:* | ||
19.0.0.245CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.245:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.