CVE-2015-8650 is a critical use-after-free vulnerability in Adobe Flash Player, AIR, and AIR SDK products across Windows, OS X, and Linux platforms. This flaw allows unauthenticated attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, requiring user interaction. While not listed in CISA's KEV catalog, the vulnerability has a high CVSS score of 8.8 and garnered significant media attention, with two articles published. Despite its age, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and community discussion is limited to two mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
<= 20.0.0.204CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* | ||
<= 18.0.0.268CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
19.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:* | ||
19.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.