CVE-2015-8651: Adobe Flash Player Integer Overflow Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 67.7% chance of exploitation in the next 30 days.

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

Affected products

  • Adobe Air: before 20.0.0.233 (fixed in 20.0.0.233)
  • Adobe Air SDK: before 20.0.0.233 (fixed in 20.0.0.233)
  • Adobe Air SDK & Compiler: before 20.0.0.233 (fixed in 20.0.0.233)
  • Adobe Flash Player: before 11.2.202.559 (fixed in 11.2.202.559); before 18.0.0.324 (fixed in 18.0.0.324); from 19.0.0.185, before 20.0.0.267 (fixed in 20.0.0.267)
  • HP Insight Control: before 7.6 (fixed in 7.6)
  • HP Insight Control Server Provisioning: before 7.6 (fixed in 7.6)
  • HP Matrix Operating Environment: version 7.6 only
  • HP System Management Homepage: before 7.6 (fixed in 7.6)
  • HP Systems Insight Manager: before 7.6 (fixed in 7.6)
  • HP Version Control Repository Manager: before 7.6 (fixed in 7.6)
  • Opensuse Evergreen: version 11.4 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
  • Suse Linux Enterprise Desktop: version 11 only; version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2015-12-28. Last modified 2026-06-17.