Skip to main content

CVE detail

CVE-2015-8446

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438.

CVSS 9.3 · CriticalBuzz score 29.0

Buzz score

Why this CVE is surfacing

Buzz score total 29.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • Based on an analysis in 2015 of over 100 exploit kits (EKs) and known vulnerabilities, Adobe Flash was the unfortunate winner of the most frequently exploited product. Now that it’s 2017, companies are joking that maybe it’s time to give Flash the old heave ho’ to retirement. While Adobe has worked tirelessly to make Flash more […]

    newswww.csoonline.comJan 17, 2017, 7:00 PM
  • The operations of TeslaCrypt, one of the largest ransomware threats over the past months, appear to have shut down, with its authors already releasing a master decryption key, researchers at ESET report.

    newswww.securityweek.comMay 19, 2016, 2:49 PM
  • The French security researcher known as “Kafeine” revealed on Tuesday that an exploit for a recently patched Microsoft Silverlight vulnerability has been added to the Angler exploit kit.

    newswww.securityweek.comFeb 24, 2016, 11:50 AM
  • A security researcher discovered a new variant of the Angler exploit kit that includes the exploit code for a recently patched Adobe Flash Player flaw. The French security researcher “Kafeine” has discovered a new variant of the popular Angler exploit kit that includes the exploit code for a recently patched Adobe Flash Player vulnerability (CVE-2015-8446). Kafeine reported […]

    newssecurityaffairs.comDec 22, 2015, 7:17 AM
  • An exploit for a recently patched Adobe Flash Player vulnerability has been added to the Angler exploit kit and it has been used by cybercriminals to deliver the file-encrypting ransomware known as TeslaCrypt.

    newswww.securityweek.comDec 21, 2015, 6:15 PM
  • Angler EK Drops TeslaCrypt Via Recent Flash ExploitMalwarebytes Labs

    On December 18, security company Fortinet blogged about a possible new variant of the CryptoWall ransomware distributed via spam. Around the same…

    newswww.malwarebytes.comDec 18, 2015, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence