CVE-2015-8651: Adobe Flash Player Integer Overflow Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 67.7% chance of exploitation in the next 30 days.
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
Affected products
- Adobe Air: before 20.0.0.233 (fixed in 20.0.0.233)
- Adobe Air SDK: before 20.0.0.233 (fixed in 20.0.0.233)
- Adobe Air SDK & Compiler: before 20.0.0.233 (fixed in 20.0.0.233)
- Adobe Flash Player: before 11.2.202.559 (fixed in 11.2.202.559); before 18.0.0.324 (fixed in 18.0.0.324); from 19.0.0.185, before 20.0.0.267 (fixed in 20.0.0.267)
- HP Insight Control: before 7.6 (fixed in 7.6)
- HP Insight Control Server Provisioning: before 7.6 (fixed in 7.6)
- HP Matrix Operating Environment: version 7.6 only
- HP System Management Homepage: before 7.6 (fixed in 7.6)
- HP Systems Insight Manager: before 7.6 (fixed in 7.6)
- HP Version Control Repository Manager: before 7.6 (fixed in 7.6)
- Opensuse Evergreen: version 11.4 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
- Suse Linux Enterprise Desktop: version 11 only; version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2015-12-28. Last modified 2026-06-17.