Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 1 of 55
CVE-2016-4117P1CRITICALCVSS 9.8KEVPoCRansomware≤ 21.0.0.2262016-05-11
CVE-2016-4117 [CRITICAL] CVE-2016-4117: Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unsp
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
nvd
CVE-2015-5119P1CRITICALCVSS 9.8KEVPoCRansomware≥ 13.0.0.182, ≤ 13.0.0296≥ 14.0.0.125, ≤ 18.0.0.194+1 more2015-07-08
CVE-2015-5119 [CRITICAL] CWE-416 CVE-2015-5119: Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Ad
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash conten
nvd
CVE-2015-3113P1CRITICALCVSS 9.8KEVPoCfixed in 13.0.0.296≥ 14.0.0.125, < 18.0.0.194+1 more2015-06-23
CVE-2015-3113 [CRITICAL] CWE-787 CVE-2015-3113: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
nvd
CVE-2015-5122P1CRITICALCVSS 9.8KEVPoCRansomware≥ 13.0, ≤ 13.0.0.302≥ 18.0, ≤ 18.0.0.203+2 more2015-07-14
CVE-2015-5122 [CRITICAL] CWE-416 CVE-2015-5122: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation i
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary c
nvd
CVE-2015-0311P1CRITICALCVSS 9.8KEVPoCRansomware≤ 11.2.202.438≤ 13.0.0.262+1 more2015-01-23
CVE-2015-0311 [CRITICAL] CVE-2015-0311: Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
nvd
CVE-2014-0497P1CRITICALCVSS 9.8KEVPoCfixed in 11.2.202.336fixed in 11.7.700.261+1 more2014-02-05
CVE-2014-0497 [CRITICAL] CWE-191 CVE-2014-0497: Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-0313P1CRITICALCVSS 9.8KEVPoCfixed in 11.2.202.442fixed in 13.0.0.269+1 more2015-02-02
CVE-2015-0313 [CRITICAL] CWE-416 CVE-2015-0313: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-20
nvd
CVE-2015-3043P1CRITICALCVSS 9.8KEVPoCfixed in 11.2.202.457fixed in 13.0.0.281+1 more2015-04-14
CVE-2015-3043 [CRITICAL] CVE-2015-3043: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-03
nvd
CVE-2018-4878P1HIGHCVSS 7.8KEVPoCRansomwarefixed in 28.0.0.1612018-02-06
CVE-2018-4878 [HIGH] CWE-416 CVE-2018-4878: A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerab
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
nvd
CVE-2011-0611P1HIGHCVSS 8.8KEVPoCfixed in 10.2.154.27≤ 10.2.156.122011-04-13
CVE-2011-0611 [HIGH] CWE-843 CVE-2011-0611: Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and e
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.
nvd
CVE-2018-15982P1HIGHCVSS 7.8KEVPoCRansomware≤ 31.0.0.1532019-01-18
CVE-2018-15982 [HIGH] CWE-416 CVE-2018-15982: Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulne
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2012-0754P1HIGHCVSS 8.1KEVPoCfixed in 10.3.183.15≥ 11.0, < 11.1.102.62+2 more2012-02-16
CVE-2012-0754 [HIGH] CWE-787 CVE-2012-0754: Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and S
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-7645P1HIGHCVSS 7.8KEVPoCRansomware≥ 18.0.0.160, ≤ 18.0.0.252v19.0.0.185+2 more2015-10-15
CVE-2015-7645 [HIGH] CVE-2015-7645: Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
nvd
CVE-2010-1297P1HIGHCVSS 7.8KEVPoCfixed in 9.0.277.0≥ 10.0, < 10.1.53.642010-06-08
CVE-2010-1297 [HIGH] CWE-787 CVE-2010-1297: Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Ad
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript
nvd
CVE-2016-0984P1HIGHCVSS 8.8KEVPoC≤ 20.0.0.272≤ 11.2.202.559+2 more2016-02-10
CVE-2016-0984 [HIGH] CVE-2016-0984: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability t
nvd
CVE-2011-0609P1HIGHCVSS 7.8KEVPoC≤ 10.2.154.13≤ 10.1.106.162011-03-15
CVE-2011-0609 [HIGH] CVE-2011-0609: Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux,
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary co
nvd
CVE-2012-1535P1HIGHCVSS 7.8KEVPoCfixed in 11.3.300.271fixed in 11.2.202.2382012-08-15
CVE-2012-1535 [HIGH] CWE-20 CVE-2012-1535: Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and befo
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.
nvd
CVE-2015-8651P1HIGHCVSS 8.8KEVRansomwarefixed in 11.2.202.559fixed in 18.0.0.324+1 more2015-12-28
CVE-2015-8651 [HIGH] CWE-190 CVE-2015-8651: Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Wind
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2014-8439P1HIGHCVSS 8.8KEVRansomware≤ 11.2.202.418≤ 15.0.0.223+1 more2014-11-25
CVE-2014-8439 [HIGH] CWE-119 CVE-2014-8439: Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and bef
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified ve
nvd
CVE-2016-1019P1CRITICALCVSS 9.8KEVRansomware≤ 18.0.0.333≤ 21.0.0.197+1 more2016-04-07
CVE-2016-1019 [CRITICAL] CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (appl
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
nvd
1 / 55Next →