Adobe Air vulnerabilities
145 known vulnerabilities affecting adobe/adobe_air.
Total CVEs
145
CISA KEV
2
actively exploited
Public exploits
5
Exploited in wild
6
Severity breakdown
CRITICAL116HIGH15MEDIUM14
Vulnerabilities
Page 7 of 8
CVE-2014-0516P3HIGHCVSS 7.5fixed in 13.0.0.1112014-05-14
CVE-2014-0516 [HIGH] CWE-264 CVE-2014-0516: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2010-2216P3CRITICALCVSS 9.3v1.0v1.0.1+4 more2010-08-11
CVE-2010-2216 [CRITICAL] CVE-2010-2216: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.
nvd
CVE-2010-0209P3CRITICALCVSS 9.3v1.0v1.0.1+4 more2010-08-11
CVE-2010-0209 [CRITICAL] CWE-94 CVE-2010-0209: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.
nvd
CVE-2010-2214P3CRITICALCVSS 9.3v1.0v1.0.1+4 more2010-08-11
CVE-2010-2214 [CRITICAL] CVE-2010-2214: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2216.
nvd
CVE-2010-2213P3CRITICALCVSS 9.3v1.0v1.0.1+4 more2010-08-11
CVE-2010-2213 [CRITICAL] CVE-2010-2213: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2214, and CVE-2010-2216.
nvd
CVE-2014-0517P3HIGHCVSS 7.5fixed in 13.0.0.1112014-05-14
CVE-2014-0517 [HIGH] CWE-264 CVE-2014-0517: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0518, CVE-2014-0519, and CVE-2014-0520.
nvd
CVE-2014-0519P3HIGHCVSS 7.5fixed in 13.0.0.1112014-05-14
CVE-2014-0519 [HIGH] CVE-2014-0519: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0518, and CVE-2014-0520.
nvd
CVE-2014-0518P3HIGHCVSS 7.5fixed in 13.0.0.1112014-05-14
CVE-2014-0518 [HIGH] CVE-2014-0518: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0519, and CVE-2014-0520.
nvd
CVE-2014-0520P3HIGHCVSS 7.5fixed in 13.0.0.1112014-05-14
CVE-2014-0520 [HIGH] CVE-2014-0520: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0518, and CVE-2014-0519.
nvd
CVE-2014-0539P3HIGHCVSS 7.5≤ 14.0.0.110v13.0.0.83+1 more2014-07-09
CVE-2014-0539 [HIGH] CVE-2014-0539: Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0537.
nvd
CVE-2014-0537P3HIGHCVSS 7.5≤ 14.0.0.110v13.0.0.83+1 more2014-07-09
CVE-2014-0537 [HIGH] CWE-264 CVE-2014-0537: Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-20
nvd
CVE-2014-0499P3HIGHCVSS 7.8fixed in 4.0.0.16282014-02-21
CVE-2014-0499 [HIGH] CWE-264 CVE-2014-0499: Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac
Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the
nvd
CVE-2011-2139P4MEDIUMCVSS 6.4≤ 2.7v1.0+8 more2011-08-10
CVE-2011-2139 [MEDIUM] CWE-264 CVE-2011-2139: Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
nvd
CVE-2015-0302P4MEDIUMCVSS 5.0≤ 15.0.0.3562015-01-13
CVE-2015-0302 [MEDIUM] CVE-2015-0302: Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and
Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow attackers to obtain sensitive keystroke information via unspec
nvd
CVE-2010-0186P4MEDIUMCVSS 6.8≤ 1.5.3.9120v1.0+4 more2010-02-15
CVE-2010-0186 [MEDIUM] CVE-2010-0186: Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and
Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
nvd
CVE-2009-3951P4HIGHCVSS 7.1≤ 1.5.2v1.0+3 more2009-12-10
CVE-2009-3951 [HIGH] CVE-2009-3951: Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.3
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
nvd
CVE-2008-5108P4MEDIUMCVSS 6.8≤ 1.1v1.02008-11-17
CVE-2008-5108 [MEDIUM] CWE-94 CVE-2008-5108: Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute
Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via unknown attack vectors.
nvd
CVE-2014-0508P4MEDIUMCVSS 5.0≤ 4.0.0.1390v1.0+55 more2014-04-08
CVE-2014-0508 [MEDIUM] CWE-264 CVE-2014-0508: Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS
Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspeci
nvd
CVE-2012-4171P4MEDIUMCVSS 5.0≤ 3.3.0.36702012-08-31
CVE-2012-4171 [MEDIUM] CVE-2012-4171: Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 1
Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allow attackers to cause a denial of service (application crash)
nvd
CVE-2014-0532P4MEDIUMCVSS 4.3≤ 13.0.0.111v13.0.0.832014-06-11
CVE-2014-0532 [MEDIUM] CVE-2014-0532: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a
nvd