VYPR
Unrated severityNVD Advisory· Published Dec 10, 2015· Updated May 6, 2026

CVE-2015-8446

CVE-2015-8446

Description

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Heap buffer overflow in Adobe Flash Player before 18.0.0.268/20.0.0.228 allows arbitrary code execution via malformed MP3 COMM tags.

Vulnerability

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x/20.x before 20.0.0.228 on Windows and OS X, and before 11.2.202.554 on Linux, also affecting Adobe AIR before 20.0.0.204. The flaw occurs when handling MP3 files: insufficient memory allocation for COMM tags leads to a heap overflow [1][2].

Exploitation

Remote attacker must convince a user to visit a malicious page or open a malicious MP3 file. No authentication required, only user interaction. The attacker crafts an MP3 with oversized COMM tags, triggering a heap buffer overflow [1].

Impact

Successful exploitation allows arbitrary code execution in the context of the current process, potentially leading to complete system compromise [1][2].

Mitigation

Adobe released updates: Flash Player 18.0.0.268, 20.0.0.228, and 11.2.202.554, and AIR 20.0.0.204. Gentoo recommends upgrading to >=11.2.202.559 [1][2]. No workaround is available.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

16

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.