cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 19 of 55
CVE-2016-0963P3HIGHCVSS 8.8≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-0963 [HIGH] CWE-190 CVE-2016-0963: Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability th
nvd
CVE-2017-3063P3CRITICALCVSS 9.8≤ 25.0.0.1272017-04-12
CVE-2017-3063 [CRITICAL] CWE-416 CVE-2017-3063: Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3084P3CRITICALCVSS 9.8≤ 25.0.0.1712017-06-20
CVE-2017-3084 [CRITICAL] CWE-416 CVE-2017-3084: Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3075P3CRITICALCVSS 9.8≤ 25.0.0.1712017-06-20
CVE-2017-3075 [CRITICAL] CWE-416 CVE-2017-3075: Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7869P3HIGHCVSS 8.8≤ 23.0.0.207≤ 11.2.202.6442016-12-15
CVE-2016-7869 [HIGH] CWE-787 CVE-2016-7869: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buf Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to backtrack search functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-3039P3CRITICALCVSS 10.0≤ 11.2.202.451≤ 13.0.0.264+15 more2015-04-14
CVE-2015-3039 [CRITICAL] CVE-2015-3039: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-0358.
nvd
CVE-2015-0351P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+15 more2015-04-14
CVE-2015-0351 [CRITICAL] CVE-2015-0351: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0358, and CVE-2015-3039.
nvd
CVE-2016-7870P3HIGHCVSS 8.8≤ 23.0.0.207≤ 11.2.202.6442016-12-15
CVE-2016-7870 [HIGH] CWE-787 CVE-2016-7870: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buf Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2014-0538P3CRITICALCVSS 10.0≤ 11.2.202.394v11.2.202.223+35 more2014-08-12
CVE-2014-0538 [CRITICAL] CVE-2014-0538: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on W Use-after-free vulnerability in Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 allows attackers to execute arbitrary code via
nvd
CVE-2015-0308P3CRITICALCVSS 10.0≤ 13.0.0.259v14.0.0.125+14 more2015-01-13
CVE-2015-0308 [CRITICAL] CVE-2015-0308: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allows attackers to execute arbitr
nvd
CVE-2017-3060P3CRITICALCVSS 9.8≤ 25.0.0.1272017-04-12
CVE-2017-3060 [CRITICAL] CWE-125 CVE-2017-3060: Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-3038P3CRITICALCVSS 10.0≤ 11.2.202.451≤ 13.0.0.264+15 more2015-04-14
CVE-2015-3038 [CRITICAL] CVE-2015-3038: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-20
nvd
CVE-2012-0756P3CRITICALCVSS 9.3fixed in 10.3.183.15≥ 11.0, < 11.1.102.62+2 more2012-02-16
CVE-2012-0756 [CRITICAL] CVE-2012-0756: Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and S Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0755.
nvd
CVE-2020-3757P3HIGHCVSS 8.8fixed in 32.0.0.321fixed in 32.0.0.314+2 more2020-02-13
CVE-2020-3757 [HIGH] CWE-843 CVE-2020-3757: Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-0356P3CRITICALCVSS 10.0≤ 11.2.202.451≤ 13.0.0.264+15 more2015-04-14
CVE-2015-0356 [CRITICAL] CVE-2015-0356: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion."
nvd
CVE-2013-0646P3CRITICALCVSS 10.0≤ 11.6.602.171v11.0+45 more2013-03-13
CVE-2013-0646 [CRITICAL] CWE-189 CVE-2013-0646: Integer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows an Integer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler before 3
nvd
CVE-2011-2426P3CRITICALCVSS 9.3≤ 10.3.183.7v6.0.21.0+94 more2011-09-22
CVE-2011-2426 [CRITICAL] CWE-119 CVE-2011-2426: Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Playe Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-8438P3CRITICALCVSS 9.3≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8438 [CRITICAL] CWE-119 CVE-2015-8438: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.2 Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a crafted XML object that is mishandle
nvd
CVE-2017-11213P3CRITICALCVSS 9.8≤ 27.0.0.1832017-12-09
CVE-2017-11213 [CRITICAL] CWE-125 CVE-2017-11213: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability oc An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque bitmap image. The use of an in
nvd
CVE-2017-2927P3HIGHCVSS 8.8≤ 24.0.0.1862017-01-11
CVE-2017-2927 [HIGH] CWE-787 CVE-2017-2927: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability w Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing Adobe Texture Format files. Successful exploitation could lead to arbitrary code execution.
nvd
Adobe Flash Player vulnerabilities | cvebase