VYPR
Unrated severityNVD Advisory· Published Dec 10, 2015· Updated May 6, 2026

CVE-2015-8456

CVE-2015-8456

Description

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-8439.

Affected products

13
  • Adobe Inc./Flashplayerinferred6 versions
    <=18.0.0.268, >=19.0<20.0.0.228, <=11.2.202.554+ 5 more
    • (no CPE)range: <=18.0.0.268, >=19.0<20.0.0.228, <=11.2.202.554
    • cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=18.0.0.261
    • cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:19.0.0.226:*:*:*:*:*:*:*
    • cpe:2.3:a:adobe:flash_player:19.0.0.245:*:*:*:*:*:*:*
  • Adobe Inc./Air2 versions
    cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=19.0.0.241
    • (no CPE)range: < 20.0.0.204
  • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*range: <=19.0.0.241
    • (no CPE)range: < 20.0.0.204
  • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*range: <=19.0.0.241
    • (no CPE)range: < 20.0.0.204
  • Range: < 18.0.0.268 (Windows/OS X), < 20.0.0.228 (19.x/20.x on Windows/OS X), < 11.2.202.554 (Linux)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.