CVE-2015-3087
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK bef...
Affects 8 products across 4 vendors.
{ "executive_summary": "A critical vulnerability exists in Adobe Flash Player and related products due to an integer overflow, which could allow attackers to execute arbitrary code.", "attack_vector_detail": "The vulnerability is caused by an integer overflow in the handling of certain data structures, which can be exploited by attackers to execute arbitrary code in the context of the affected application. Attackers can exploit this vulnerability by enticing a user to open a specially crafted SWF file or visit a malicious website.", "affected_components": [ "Adobe Flash Player before 13.0.0.289", "Adobe Flash Player 14.x through 17.x before 17.0.0.188 on Windows and OS X", "Adobe Flash Player before 11.2.202.460 on Linux", "Adobe AIR before 17.0.0.172", "Adobe AIR SDK before 17.0.0.172", "Adobe AIR SDK & Compiler before 17.0.0.172" ], "exploitation_likelihood": "CRITICAL", "remediation_priority
BSID: BS-2015-GLOBAL-170149-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2015-3087?
What is the CVSS score for CVE-2015-3087?
Is CVE-2015-3087 actively exploited?
How do I remediate CVE-2015-3087?
What systems are affected by CVE-2015-3087?
| CVE ID | CVE-2015-3087 |
|---|---|
| BSID | BS-2015-GLOBAL-170149-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2015-05-13 |
| Last Modified | 2026-05-06 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Adobe | Air Sdk & Compiler | — |
| Adobe | Air | — |
| Adobe | Air Sdk | — |
| Adobe | Air Sdk \& Compiler | — |
| Adobe | Flash Player | — |
| Apple | Mac Os X | — |
| Linux | Linux Kernel | — |
| Microsoft | Windows | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Enriched At | 2026-05-25 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →