cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 16 of 55
CVE-2015-3135P3CRITICALCVSS 10.0≤ 13.0.0.289v14.0.0.125+20 more2015-07-09
CVE-2015-3135 [CRITICAL] CWE-119 CVE-2015-3135: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different v
nvd
CVE-2013-3344P3CRITICALCVSS 10.0≤ 11.7.700.225v11.0+58 more2013-07-10
CVE-2013-3344 [CRITICAL] CWE-119 CVE-2013-3344: Heap-based buffer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 o Heap-based buffer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-0314P3CRITICALCVSS 10.0≤ 11.2.202.440≤ 13.0.0.264+14 more2015-02-06
CVE-2015-0314 [CRITICAL] CVE-2015-0314: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, CVE-2015-0329, and CVE-2015-0330.
nvd
CVE-2015-0329P3CRITICALCVSS 10.0≤ 11.2.202.440≤ 13.0.0.264+14 more2015-02-06
CVE-2015-0329 [CRITICAL] CVE-2015-0329: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, and CVE-2015-0330.
nvd
CVE-2015-0321P3CRITICALCVSS 10.0≤ 11.2.202.440≤ 13.0.0.264+14 more2015-02-06
CVE-2015-0321 [CRITICAL] CVE-2015-0321: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0329, and CVE-2015-0330.
nvd
CVE-2015-0316P3CRITICALCVSS 10.0≤ 11.2.202.440≤ 13.0.0.264+14 more2015-02-06
CVE-2015-0316 [CRITICAL] CVE-2015-0316: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0318, CVE-2015-0321, CVE-2015-0329, and CVE-2015-0330.
nvd
CVE-2015-8459P3CRITICALCVSS 10.0≤ 11.2.202.554≤ 18.0.0.268+6 more2015-12-28
CVE-2015-8459 [CRITICAL] CWE-119 CVE-2015-8459: Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and bef Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors,
nvd
CVE-2011-0577P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0577 [CRITICAL] CVE-2011-0577: Unspecified vulnerability in Adobe Flash Player before 10.2.152.26 allows remote attackers to execut Unspecified vulnerability in Adobe Flash Player before 10.2.152.26 allows remote attackers to execute arbitrary code via a crafted font.
nvd
CVE-2017-3114P3CRITICALCVSS 9.8≤ 27.0.0.1832017-12-09
CVE-2017-3114 [CRITICAL] CWE-125 CVE-2017-3114: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability oc An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during acce
nvd
CVE-2016-1018P3HIGHCVSS 8.8≤ 11.2.202.577≤ 18.0.0.333+1 more2016-04-09
CVE-2016-1018 [HIGH] CWE-787 CVE-2016-1018: Stack-based buffer overflow in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21. Stack-based buffer overflow in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via crafted JPEG-XR data.
nvd
CVE-2018-15981P3CRITICALCVSS 9.8≤ 31.0.0.148v31.0.0.148 and earlier versions2018-11-29
CVE-2018-15981 [CRITICAL] CWE-704 CVE-2018-15981: Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploit Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-8445P3CRITICALCVSS 9.3≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8445 [CRITICAL] CWE-189 CVE-2015-8445: Integer overflow in the Shader filter implementation in Adobe Flash Player before 18.0.0.268 and 19. Integer overflow in the Shader filter implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a large Bitm
nvd
CVE-2012-5276P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.43≥ 11.4, < 11.5.502.110+3 more2012-11-07
CVE-2012-5276 [CRITICAL] CVE-2012-5276: Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code vi
nvd
CVE-2012-5275P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.43≥ 11.4, < 11.5.502.110+3 more2012-11-07
CVE-2012-5275 [CRITICAL] CVE-2012-5275: Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code vi
nvd
CVE-2012-5277P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.43≥ 11.4, < 11.5.502.110+3 more2012-11-07
CVE-2012-5277 [CRITICAL] CVE-2012-5277: Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code vi
nvd
CVE-2012-5274P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.43≥ 11.4, < 11.5.502.110+3 more2012-11-07
CVE-2012-5274 [CRITICAL] CWE-119 CVE-2012-5274: Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary
nvd
CVE-2015-0358P3CRITICALCVSS 10.0≤ 11.2.202.451≤ 13.0.0.264+15 more2015-04-14
CVE-2015-0358 [CRITICAL] CVE-2015-0358: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-3039.
nvd
CVE-2015-0346P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+15 more2015-04-14
CVE-2015-0346 [CRITICAL] CVE-2015-0346: Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0. Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359.
nvd
CVE-2013-1369P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.63≥ 11.6, < 11.6.602.168+5 more2013-02-12
CVE-2013-1369 [CRITICAL] CVE-2013-1369: Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, be Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.5
nvd
CVE-2013-0642P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.63≥ 11.6, < 11.6.602.168+5 more2013-02-12
CVE-2013-0642 [CRITICAL] CWE-119 CVE-2013-0642: Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, be Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before
nvd
Adobe Flash Player vulnerabilities | cvebase