Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 12 of 55
CVE-2015-8457P3CRITICALCVSS 10.0≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8457 [CRITICAL] CVE-2015-8457: Stack-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.
Stack-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabilit
nvd
CVE-2015-0309P3CRITICALCVSS 10.0≤ 13.0.0.259v14.0.0.125+14 more2015-01-13
CVE-2015-0309 [CRITICAL] CVE-2015-0309: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allows attackers to execute arbitrar
nvd
CVE-2015-0304P3CRITICALCVSS 10.0≤ 13.0.0.259v14.0.0.125+14 more2015-01-13
CVE-2015-0304 [CRITICAL] CWE-119 CVE-2015-0304: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allows attackers to execute
nvd
CVE-2015-8407P3CRITICALCVSS 10.0≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8407 [CRITICAL] CWE-119 CVE-2015-8407: Stack-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.
Stack-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vuln
nvd
CVE-2015-3081P3MEDIUMCVSS 4.3PoC≤ 11.2.202.475≤ 13.0.0.264+16 more2015-05-13
CVE-2015-3081 [MEDIUM] CWE-362 CVE-2015-3081: Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Wi
Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to bypass the Internet Explorer Protected Mode protection mechanism via unspec
nvd
CVE-2015-3100P3CRITICALCVSS 10.0≤ 11.2.202.460≤ 13.0.0.289+17 more2015-06-10
CVE-2015-3100 [CRITICAL] CWE-119 CVE-2015-3100: Stack-based buffer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler befo
nvd
CVE-2013-0639P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.63≥ 11.6, < 11.6.602.168+5 more2013-02-12
CVE-2013-0639 [CRITICAL] CWE-189 CVE-2013-0639: Integer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, b
Integer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK befor
nvd
CVE-2014-0582P3CRITICALCVSS 10.0≥ 13.0, < 13.0.0.252≥ 14.0, ≤ 14.0.0.179+2 more2014-11-11
CVE-2014-0582 [CRITICAL] CWE-119 CVE-2014-0582: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.2
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulne
nvd
CVE-2012-5285P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.29≥ 11.4, < 11.4.402.287+3 more2012-11-13
CVE-2012-5285 [CRITICAL] CWE-119 CVE-2012-5285: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and
Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2013-0630P3CRITICALCVSS 10.0≤ 10.3.183.48v10.3.181.14+29 more2013-01-11
CVE-2013-0630 [CRITICAL] CWE-119 CVE-2013-0630: Buffer overflow in Adobe Flash Player before 10.3.183.50 and 11.x before 11.5.502.146 on Windows and
Buffer overflow in Adobe Flash Player before 10.3.183.50 and 11.x before 11.5.502.146 on Windows and Mac OS X, before 10.3.183.50 and 11.x before 11.2.202.261 on Linux, before 11.1.111.31 on Android 2.x and 3.x, and before 11.1.115.36 on Android 4.x; Adobe AIR before 3.5.0.1060; and Adobe AIR SDK before 3.5.0.1060 allows attackers to execute arbitra
nvd
CVE-2017-3083P3CRITICALCVSS 9.8≤ 25.0.0.1712017-06-20
CVE-2017-3083 [CRITICAL] CWE-416 CVE-2017-3083: Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3081P3CRITICALCVSS 9.8≤ 25.0.0.1712017-06-20
CVE-2017-3081 [CRITICAL] CWE-416 CVE-2017-3081: Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4222P3HIGHCVSS 8.8≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4222 [HIGH] CVE-2016-4222: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-423
nvd
CVE-2016-0994P3HIGHCVSS 8.8≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-0994 [HIGH] CVE-2016-0994: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafte
nvd
CVE-2015-5541P3CRITICALCVSS 10.0≤ 11.2.202.491≤ 18.0.0.2092015-08-14
CVE-2015-5541 [CRITICAL] CVE-2015-5541: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5129.
nvd
CVE-2016-6931P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-6931 [HIGH] CVE-2016-6931: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4272, CVE-2016-4279, CVE-2016-6921, CVE-2016-6923, CVE-2016-6925, CVE-2016-6926, CVE-2016-692
nvd
CVE-2015-5129P3CRITICALCVSS 10.0≤ 11.2.202.491≤ 18.0.0.2092015-08-14
CVE-2015-5129 [CRITICAL] CWE-119 CVE-2015-5129: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5541.
nvd
CVE-2016-0996P3HIGHCVSS 8.8≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-0996 [HIGH] CVE-2016-0996: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 1
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments,
nvd
CVE-2016-4248P3HIGHCVSS 8.8≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4248 [HIGH] CVE-2016-4248: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4222, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-422
nvd
CVE-2013-1375P3CRITICALCVSS 10.0≤ 11.6.602.171v11.0+45 more2013-03-13
CVE-2013-1375 [CRITICAL] CWE-119 CVE-2013-1375: Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on
Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler
nvd