Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 10 of 55
CVE-2016-1105P2HIGHCVSS 7.5PoC≤ 21.0.0.2132016-05-11
CVE-2016-1105 [HIGH] CVE-2016-1105: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4108P2HIGHCVSS 7.5PoC≤ 21.0.0.2132016-05-11
CVE-2016-4108 [HIGH] CVE-2016-4108: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1103P2HIGHCVSS 7.5PoC≤ 21.0.0.2132016-05-11
CVE-2016-1103 [HIGH] CVE-2016-1103: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1101P2HIGHCVSS 7.5PoC≤ 21.0.0.2132016-05-11
CVE-2016-1101 [HIGH] CVE-2016-1101: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1106P2HIGHCVSS 7.5PoC≤ 21.0.0.2132016-05-11
CVE-2016-1106 [HIGH] CVE-2016-1106: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2017-2985P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2985 [HIGH] CWE-416 CVE-2017-2985: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-8636P2HIGHCVSS 8.8PoC≤ 18.0.0.268v19.0.0.185+6 more2015-12-28
CVE-2015-8636 [HIGH] CVE-2015-8636: Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and bef
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different
nvd
CVE-2017-2931P2HIGHCVSS 8.8PoC≤ 24.0.0.1862017-01-11
CVE-2017-2931 [HIGH] CWE-787 CVE-2017-2931: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerabili
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3068P2HIGHCVSS 8.8PoC≤ 25.0.0.1482017-05-09
CVE-2017-3068 [HIGH] CWE-787 CVE-2017-3068: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2988P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2988 [HIGH] CWE-787 CVE-2017-2988: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerabili
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing garbage collection. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3106P2HIGHCVSS 8.8PoC≤ 26.0.0.1372017-08-11
CVE-2017-3106 [HIGH] CWE-704 CVE-2017-3106: Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-7652P2CRITICALCVSS 9.3PoC≤ 18.0.0.255v19.0.0.185+3 more2015-11-11
CVE-2015-7652 [CRITICAL] CVE-2015-7652: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via a crafted gridFitType property value, a different vul
nvd
CVE-2016-4176P2HIGHCVSS 8.8PoC≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4176 [HIGH] CWE-787 CVE-2016-4176: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4177.
nvd
CVE-2016-4177P2HIGHCVSS 8.8PoC≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4177 [HIGH] CVE-2016-4177: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4176.
nvd
CVE-2016-4135P2HIGHCVSS 8.8PoC≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4135 [HIGH] CVE-2016-4135: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4137P2HIGHCVSS 8.8PoC≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4137 [HIGH] CVE-2016-4137: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4136P2HIGHCVSS 8.8PoC≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4136 [HIGH] CVE-2016-4136: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2015-5568P2CRITICALCVSS 10.0PoC≤ 11.2.202.508≤ 13.0.0.289+24 more2015-09-22
CVE-2015-5568 [CRITICAL] CWE-20 CVE-2015-5568: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via unknown
nvd
CVE-2018-12827P2HIGHCVSS 7.5PoC≤ 30.0.0.1542018-08-29
CVE-2018-12827 [HIGH] CWE-125 CVE-2018-12827: Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful explo
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2015-8635P2HIGHCVSS 8.8PoC≤ 11.2.202.554≤ 18.0.0.268+6 more2015-12-28
CVE-2015-8635 [HIGH] CVE-2015-8635: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability t
nvd