CVE-2015-3087

CRITICAL ⚠ Exploit

Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK bef...

Affects 8 products across 4 vendors.

BCS8.97
CVSS 2.010.0
EPSS74.3%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-189: CWE-189
◆ SAGE Intelligence — CITED Relevance Research Team

{ "executive_summary": "A critical vulnerability exists in Adobe Flash Player and related products due to an integer overflow, which could allow attackers to execute arbitrary code.", "attack_vector_detail": "The vulnerability is caused by an integer overflow in the handling of certain data structures, which can be exploited by attackers to execute arbitrary code in the context of the affected application. Attackers can exploit this vulnerability by enticing a user to open a specially crafted SWF file or visit a malicious website.", "affected_components": [ "Adobe Flash Player before 13.0.0.289", "Adobe Flash Player 14.x through 17.x before 17.0.0.188 on Windows and OS X", "Adobe Flash Player before 11.2.202.460 on Linux", "Adobe AIR before 17.0.0.172", "Adobe AIR SDK before 17.0.0.172", "Adobe AIR SDK & Compiler before 17.0.0.172" ], "exploitation_likelihood": "CRITICAL", "remediation_priority

BSID: BS-2015-GLOBAL-170149-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2015-3087?
{ "executive_summary": "A critical vulnerability exists in Adobe Flash Player and related products due to an integer overflow, which could allow attackers to execute arbitrary code.", "attack_vector_detail": "The vulnerability is caused by an integer overflow in the handling of certain data structures, which can be exploited by attackers to execute arbitrary code in the context of the affected application. Attackers can exploit this vulnerability by enticing a user to open a specially crafte
What is the CVSS score for CVE-2015-3087?
CVE-2015-3087 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 74.3%.
Is CVE-2015-3087 actively exploited?
Public exploit available for CVE-2015-3087. Exploitation risk elevated.
How do I remediate CVE-2015-3087?
Advisory: https://helpx.adobe.com/security/products/flash-player/apsb15-09.html PSIRT: [email protected]
What systems are affected by CVE-2015-3087?
CVE-2015-3087 affects: Adobe, Adobe, Adobe, Adobe, Adobe, Apple, Linux, Microsoft.
Vulnerability Details
CVE IDCVE-2015-3087
BSIDBS-2015-GLOBAL-170149-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2015-05-13
Last Modified2026-05-06
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Adobe Air Sdk & Compiler
Adobe Air
Adobe Air Sdk
Adobe Air Sdk \& Compiler
Adobe Flash Player
Apple Mac Os X
Linux Linux Kernel
Microsoft Windows
Remediation
View Vendor Advisory →
Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 4103 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
Enriched At2026-05-25
Related CVEs affecting Adobe
CVE-2013-3357 10.0 Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11... CVE-2009-3956 10.0 The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x... CVE-2015-3064 10.0 Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windo... CVE-2015-0324 10.0 Buffer overflow in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x... CVE-2011-2445 10.0 Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows,...
View all Adobe CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →