cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 14 of 55
CVE-2012-5255P3CRITICALCVSS 10.0≤ 10.3.183.25v10.1.85.3+37 more2012-10-09
CVE-2012-5255 [CRITICAL] CWE-119 CVE-2012-5255: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2012-5254P3CRITICALCVSS 10.0≤ 10.3.183.25v10.1.85.3+37 more2012-10-09
CVE-2012-5254 [CRITICAL] CWE-119 CVE-2012-5254: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2012-5266P3CRITICALCVSS 10.0≤ 10.3.183.25v10.1.85.3+37 more2012-10-09
CVE-2012-5266 [CRITICAL] CWE-119 CVE-2012-5266: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2012-5251P3CRITICALCVSS 10.0≤ 10.3.183.25v10.1.85.3+37 more2012-10-09
CVE-2012-5251 [CRITICAL] CWE-119 CVE-2012-5251: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2012-5250P3CRITICALCVSS 10.0≤ 10.3.183.25v10.1.85.3+37 more2012-10-09
CVE-2012-5250 [CRITICAL] CWE-119 CVE-2012-5250: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2012-5257P3CRITICALCVSS 10.0≤ 10.3.183.25v10.1.85.3+37 more2012-10-09
CVE-2012-5257 [CRITICAL] CWE-119 CVE-2012-5257: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2012-5265P3CRITICALCVSS 10.0≤ 10.3.183.25v10.1.85.3+37 more2012-10-09
CVE-2012-5265 [CRITICAL] CWE-119 CVE-2012-5265: Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitra
nvd
CVE-2015-7632P3CRITICALCVSS 9.3≤ 11.2.202.521≤ 19.0.0.1852015-10-15
CVE-2015-7632 [CRITICAL] CWE-119 CVE-2015-7632: Buffer overflow in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS Buffer overflow in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via a Loader object with a crafted loaderBytes property.
nvd
CVE-2008-4824P3CRITICALCVSS 9.3≥ 9.0.16.0, < 9.0.151.0≥ 10, < 10.0.12.362008-11-17
CVE-2008-4824 [CRITICAL] CWE-20 CVE-2008-4824: Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0 Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."
nvd
CVE-2017-3082P3CRITICALCVSS 9.8≤ 25.0.0.1712017-06-20
CVE-2017-3082 [CRITICAL] CWE-119 CVE-2017-3082: Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2012-5280P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.43≥ 11.4, < 11.5.502.110+3 more2012-11-07
CVE-2012-5280 [CRITICAL] CVE-2012-5280: Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code vi
nvd
CVE-2015-8445P3CRITICALCVSS 9.3≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8445 [CRITICAL] CWE-189 CVE-2015-8445: Integer overflow in the Shader filter implementation in Adobe Flash Player before 18.0.0.268 and 19. Integer overflow in the Shader filter implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a large Bitm
nvd
CVE-2016-4224P3HIGHCVSS 8.8≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4224 [HIGH] CVE-2016-4224: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2016-4223 and CVE-2016-4225.
nvd
CVE-2016-4223P3HIGHCVSS 8.8≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4223 [HIGH] CWE-843 CVE-2016-4223: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2016-4224 and CVE-2016-4225.
nvd
CVE-2016-4225P3HIGHCVSS 8.8≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4225 [HIGH] CVE-2016-4225: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2016-4223 and CVE-2016-4224.
nvd
CVE-2015-0346P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+15 more2015-04-14
CVE-2015-0346 [CRITICAL] CVE-2015-0346: Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0. Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359.
nvd
CVE-2016-0990P3HIGHCVSS 8.8≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-0990 [HIGH] CVE-2016-0990: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2015-0320P3CRITICALCVSS 10.0≤ 11.2.202.440≤ 13.0.0.264+14 more2015-02-06
CVE-2015-0320 [CRITICAL] CVE-2015-0320: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.
nvd
CVE-2015-0315P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+14 more2015-02-06
CVE-2015-0315 [CRITICAL] CVE-2015-0315: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0320, and CVE-2015-0322.
nvd
CVE-2013-0504P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.67≥ 11.6, < 11.6.602.168+1 more2013-02-27
CVE-2013-0504 [CRITICAL] CWE-119 CVE-2013-0504: Buffer overflow in the broker service in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6. Buffer overflow in the broker service in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows attackers to execute arbitrary code via unspecified vectors.
nvd