cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 18 of 55
CVE-2015-3086P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+16 more2015-05-13
CVE-2015-3086 [CRITICAL] CVE-2015-3086: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than
nvd
CVE-2015-3084P3CRITICALCVSS 10.0≤ 11.2.202.475≤ 13.0.0.264+16 more2015-05-13
CVE-2015-3084 [CRITICAL] CVE-2015-3084: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than
nvd
CVE-2015-6676P3CRITICALCVSS 10.0≤ 11.2.202.508≤ 13.0.0.289+24 more2015-09-22
CVE-2015-6676 [CRITICAL] CWE-119 CVE-2015-6676: Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-20
nvd
CVE-2011-2414P3CRITICALCVSS 10.0≤ 10.3.181.36v6.0.21.0+90 more2011-08-10
CVE-2011-2414 [CRITICAL] CVE-2011-2414: Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2134, CVE-2011-2137,
nvd
CVE-2011-2415P3CRITICALCVSS 10.0≤ 10.3.181.36v6.0.21.0+90 more2011-08-10
CVE-2011-2415 [CRITICAL] CVE-2011-2415: Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2134, CVE-2011-2137,
nvd
CVE-2017-3112P3CRITICALCVSS 9.8≤ 27.0.0.1832017-12-09
CVE-2017-3112 [CRITICAL] CWE-125 CVE-2017-3112: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability oc An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the
nvd
CVE-2015-5573P3CRITICALCVSS 10.0≤ 13.0.0.289v14.0.0.125+24 more2015-09-22
CVE-2015-5573 [CRITICAL] CVE-2015-5573: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion."
nvd
CVE-2011-2134P3CRITICALCVSS 10.0≤ 10.3.181.36v6.0.21.0+90 more2011-08-10
CVE-2011-2134 [CRITICAL] CVE-2011-2134: Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2137, CVE-2011-2414,
nvd
CVE-2011-2130P3CRITICALCVSS 10.0≤ 10.3.181.36v6.0.21.0+90 more2011-08-10
CVE-2011-2130 [CRITICAL] CWE-119 CVE-2011-2130: Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2134, CVE-2011-2137, CVE-20
nvd
CVE-2011-2137P3CRITICALCVSS 10.0≤ 10.3.181.36v6.0.21.0+90 more2011-08-10
CVE-2011-2137 [CRITICAL] CVE-2011-2137: Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2134, CVE-2011-2414,
nvd
CVE-2014-0536P3CRITICALCVSS 10.0≤ 11.2.202.359≤ 13.0.0.214+3 more2014-06-11
CVE-2014-0536 [CRITICAL] CWE-119 CVE-2014-0536: Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2013-3347P3CRITICALCVSS 10.0≤ 11.7.700.224v11.0+58 more2013-07-10
CVE-2013-3347 [CRITICAL] CWE-189 CVE-2013-3347: Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.
nvd
CVE-2016-4287P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4287 [HIGH] CWE-190 CVE-2016-4287: Integer overflow in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Integer overflow in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-1015P3HIGHCVSS 8.8≤ 11.2.202.577≤ 18.0.0.333+1 more2016-04-09
CVE-2016-1015 [HIGH] CWE-843 CVE-2016-1015: Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code by overriding NetConnection object properties to leverage an unspecified "type confusion," a different vulnerability than CVE-2016-1019.
nvd
CVE-2019-8069P3CRITICALCVSS 9.8≤ 32.0.0.238≤ 32.0.0.207+2 more2019-09-12
CVE-2019-8069 [CRITICAL] CWE-346 CVE-2019-8069: Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Orig Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
nvd
CVE-2014-8438P3CRITICALCVSS 10.0≥ 13.0, < 13.0.0.252≥ 14.0, ≤ 14.0.0.179+2 more2014-11-11
CVE-2014-8438 [CRITICAL] CVE-2014-8438: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2014-0553P3CRITICALCVSS 10.0≤ 13.0.0.241v13.0.0.182+40 more2014-09-10
CVE-2014-0553 [CRITICAL] CVE-2014-0553: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary
nvd
CVE-2016-1016P3HIGHCVSS 8.8≤ 11.2.202.577≤ 18.0.0.333+1 more2016-04-09
CVE-2016-1016 [HIGH] CVE-2016-1016: Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18. Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via a flash.geom.Matrix callback, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1017, and CVE-2
nvd
CVE-2017-3062P3CRITICALCVSS 9.8≤ 25.0.0.1272017-04-12
CVE-2017-3062 [CRITICAL] CWE-416 CVE-2017-3062: Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-0993P3HIGHCVSS 8.8≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-0993 [HIGH] CVE-2016-0993: Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2
nvd
Adobe Flash Player vulnerabilities | cvebase