cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 11 of 55
CVE-2015-8634P2HIGHCVSS 8.8PoC≤ 18.0.0.268v19.0.0.185+6 more2015-12-28
CVE-2015-8634 [HIGH] CVE-2015-8634: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability t
nvd
CVE-2009-0520P3CRITICALCVSS 9.3PoC≤ 10.0.12.36v7.0+30 more2009-02-26
CVE-2009-0520 [CRITICAL] CWE-119 CVE-2009-0520: Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove referenc Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."
nvd
CVE-2010-3639P3CRITICALCVSS 9.3PoC≥ 9.0, < 9.0.289.0≥ 10.0, < 10.1.102.64+1 more2010-11-07
CVE-2010-3639 [CRITICAL] CVE-2010-3639: Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Wind Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-3082P3MEDIUMCVSS 6.4PoC≤ 13.0.0.264v14.0.0.125+16 more2015-05-13
CVE-2015-3082 [MEDIUM] CWE-264 CVE-2015-3082: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow remote attackers to bypass intended restrictions on filesystem write operations via unspecified vectors, a
nvd
CVE-2015-3083P3MEDIUMCVSS 6.4PoC≤ 11.2.202.475≤ 13.0.0.264+16 more2015-05-13
CVE-2015-3083 [MEDIUM] CVE-2015-3083: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow remote attackers to bypass intended restrictions on filesystem write operations via unspecified vectors, a differen
nvd
CVE-2009-1868P3CRITICALCVSS 9.3PoC≤ 10.0.22.87v7.0+29 more2009-07-31
CVE-2009-1868 [CRITICAL] CWE-119 CVE-2009-1868: Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Ad Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.
nvd
CVE-2018-4936P3MEDIUMCVSS 6.5PoC≤ 29.0.0.1132018-05-19
CVE-2018-4936 [MEDIUM] CWE-119 CVE-2018-4936: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2009-1869P3CRITICALCVSS 9.3PoC≤ 10.0.22.87v7.0+29 more2009-07-31
CVE-2009-1869 [CRITICAL] CWE-189 CVE-2009-1869: Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player b Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of
nvd
CVE-2017-3064P3HIGHCVSS 7.8PoC≤ 25.0.0.1272017-04-12
CVE-2017-3064 [HIGH] CWE-119 CVE-2017-3064: Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-8652P3HIGHCVSS 8.8PoC≤ 11.2.202.548≤ 18.0.0.261+1 more2016-03-04
CVE-2015-8652 [HIGH] CVE-2015-8652: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via crafted M
nvd
CVE-2018-4934P3MEDIUMCVSS 6.5PoC≤ 29.0.0.1132018-05-19
CVE-2018-4934 [MEDIUM] CWE-125 CVE-2018-4934: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerabil Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2015-5116P3MEDIUMCVSS 5.0PoC≤ 13.0.0.289v14.0.0.125+20 more2015-07-09
CVE-2015-5116 [MEDIUM] CVE-2015-5116: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2014-
nvd
CVE-2014-4671P3MEDIUMCVSS 4.3PoC≤ 11.2.202.378v11.2.202.223+32 more2014-07-09
CVE-2014-4671 [MEDIUM] CWE-352 CVE-2014-4671: Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (
nvd
CVE-2015-5587P3CRITICALCVSS 10.0≤ 11.2.202.508≤ 13.0.0.289+24 more2015-09-22
CVE-2015-5587 [CRITICAL] CWE-119 CVE-2015-5587: Stack-based buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Wi Stack-based buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-4121P3CRITICALCVSS 9.8≤ 21.0.0.241≤ 18.0.0.343+2 more2016-06-16
CVE-2016-4121 [CRITICAL] CVE-2016-4121: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1097, CVE-2016-1106, CVE-2016-1107, CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016
nvd
CVE-2015-8415P3CRITICALCVSS 10.0≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8415 [CRITICAL] CWE-119 CVE-2015-8415: Buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windo Buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2018-5007P3HIGHCVSS 8.8≤ 30.0.0.1132018-07-20
CVE-2018-5007 [HIGH] CWE-704 CVE-2018-5007: Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful e Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2015-3077P3CRITICALCVSS 10.0≤ 11.2.202.475≤ 13.0.0.264+16 more2015-05-13
CVE-2015-3077 [CRITICAL] CVE-2015-3077: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than
nvd
CVE-2017-2984P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2984 [HIGH] CWE-787 CVE-2017-2984: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability i Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the h264 decoder routine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2014-0559P3CRITICALCVSS 10.0≤ 13.0.0.241v13.0.0.182+40 more2014-09-10
CVE-2014-0559 [CRITICAL] CVE-2014-0559: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.1 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary co
nvd
Adobe Flash Player vulnerabilities | cvebase