Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2015-3105 — AIR

CVE-2015-3105 is a Buffer Overflow vulnerability in adobe air. 2 public exploit references exist, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before…

Published
Updated
Affected
5 products
Patched
See advisory
Exploits
2 known
Exploitation data as of Oct 4, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
90.1%probability of exploitation in next 30 days
Very High Risk0.00%
Lower risk than most CVEs100th percentile — riskier than 100% of all scored CVEsHighest risk
78.7%85.8%92.9%100.0%90.3%90.1%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Affected Products

5 products · 24 configurations
Application
airadobe
≤ 17.0.0.144
range
Application
air sdkadobe
≤ 17.0.0.172
range
Application
air sdk \& compileradobe
≤ 17.0.0.172
range
Application
flash playeradobe
≤ 13.0.0.289
17 versions
14.0.0.12514.0.0.14514.0.0.17614.0.0.17915.0.0.15215.0.0.16715.0.0.18915.0.0.22315.0.0.23915.0.0.24616.0.0.23516.0.0.257
OS
androidgoogle
all
Exploits & PoCs
2

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-37448remotemultiple✓ Verified

Adobe Flash Player - Drawing Fill Shader Memory Corruption (Metasploit)

by Metasploit · Jun 30, 2015

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every adobe air deployment and check each version against the affected-products list above.

  2. Remediation status

    No patch has shipped for CVE-2015-3105 yet — track the adobe air advisory for a fixed release and apply the workarounds below in the meantime.

  3. Mitigate without a patch

    Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatCritical
ProductFixed inAdvisory
Red Hat Enterprise Linux 5 Supplementaryflash-plugin-0:11.2.202.466-1.el5RHSA-2015:1086

Frequently Asked Questions

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
O3 Security · Runtime Protection

Is CVE-2015-3105 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

CVE-2015-3105: AIR Memory Corruption