CVE-2015-8651: Adobe Flash Player Integer Overflow Vulnerability

Published Dec 28, 2015
·
Updated

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

Other sources

Integer overflow in Adobe Flash Player allows attackers to execute code.

CISA

Affected Software

51 affected components
Adobe Flash Player
Adobe AIR SDK<=20.0.0.204
Adobe Air Sdk \& Compiler<=20.0.0.204
Apple iPhone OS
Apple iOS and macOS
Google Android
Microsoft Windows
Adobe Flash Player<=11.2.202.554
Linux Linux kernel
Adobe AIR<=20.0.0.204
Adobe Flash Player<=18.0.0.268
Adobe Flash Player=19.0.0.185
Adobe Flash Player=19.0.0.207
Adobe Flash Player=19.0.0.226
Adobe Flash Player=19.0.0.245
Adobe Flash Player=20.0.0.228
Adobe Flash Player=20.0.0.235
All of the following
Any of the following
Adobe AIR SDK<20.0.0.233
Adobe Air Sdk \& Compiler<20.0.0.233
Any of the following
Apple iPhone OS
Google Android
Microsoft Windows
All of the following
Adobe Flash Player<11.2.202.559
Linux Linux kernel
All of the following
Adobe AIR<20.0.0.233
Any of the following
Google Android
Microsoft Windows
All of the following
Any of the following
Adobe Flash Player<18.0.0.324
Adobe Flash Player>=19.0.0.185<20.0.0.267
Microsoft Windows
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
openSUSE Evergreen=11.4
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Desktop=11-sp3
SUSE Linux Enterprise Desktop=11-sp4
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Workstation Extension=12
SUSE Linux Enterprise Workstation Extension=12-sp1
HP Insight Control<7.6
HP Insight Control Server Provisioning<7.6
HP Matrix Operating Environment=7.6
HP System Management Homepage<7.6
HP Systems Insight Manager<7.6
HP Version Control Repository Manager<7.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    If Adobe Flash Player/AIR/AIR SDK (including AIR SDK & Compiler) is still in use, disconnect it from the network because the impacted product is end-of-life.

Event History

Dec 28, 2015
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 25, 2022
Known Exploited
via CISA·12:00 AM
Mar 1, 58274
Event
via NVD·01:21 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-8651?

CVE-2015-8651 is rated as critical due to its potential to allow remote code execution.

2

How do I fix CVE-2015-8651?

To mitigate CVE-2015-8651, update Adobe Flash Player to version 18.0.0.324 or later, or update Adobe AIR to at least version 20.0.0.233.

3

Which versions of Adobe Flash Player are affected by CVE-2015-8651?

Adobe Flash Player versions prior to 18.0.0.324, specifically 19.x and 20.x version before 20.0.0.267, are affected by CVE-2015-8651.

4

Is Adobe AIR affected by CVE-2015-8651?

Yes, Adobe AIR versions before 20.0.0.233 are vulnerable to CVE-2015-8651.

5

What platforms are impacted by CVE-2015-8651?

CVE-2015-8651 affects Adobe Flash Player on Windows, OS X, and Linux, as well as Adobe AIR across these platforms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203