cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 2 of 55
CVE-2016-4171P1CRITICALCVSS 9.8KEV≤ 11.2.202.621≤ 21.0.0.242+1 more2016-06-16
CVE-2016-4171 [CRITICAL] CVE-2016-4171: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to ex Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
nvd
CVE-2015-5123P1CRITICALCVSS 9.8KEV≥ 11.0, ≤ 11.2.202.481≥ 13.0, ≤ 13.0.0.302+1 more2015-07-14
CVE-2015-5123 [CRITICAL] CWE-416 CVE-2015-5123: Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in A Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code
nvd
CVE-2014-0502P1HIGHCVSS 8.8KEVfixed in 11.7.700.269≥ 11.8.800.94, < 12.0.0.70+1 more2014-02-21
CVE-2014-0502 [HIGH] CWE-415 CVE-2014-0502: Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified
nvd
CVE-2016-7855P1HIGHCVSS 8.8KEV≤ 23.0.0.185≤ 11.2.202.6372016-11-01
CVE-2016-7855 [HIGH] CWE-416 CVE-2016-7855: Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
nvd
CVE-2015-0310P1HIGHCVSS 7.8KEVRansomwarefixed in 11.2.202.438fixed in 13.0.0.262+1 more2015-01-23
CVE-2015-0310 [HIGH] CWE-200 CVE-2015-0310: Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the
nvd
CVE-2016-1010P1HIGHCVSS 8.8KEV≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-1010 [HIGH] CVE-2016-1010: Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2
nvd
CVE-2012-5054P1HIGHCVSS 8.8KEVfixed in 11.4.402.2652012-09-24
CVE-2012-5054 [HIGH] CWE-190 CVE-2012-5054: Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4 Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.
nvd
CVE-2016-7892P1HIGHCVSS 8.8KEV≤ 23.0.0.207≤ 11.2.202.6442016-12-15
CVE-2016-7892 [HIGH] CWE-416 CVE-2016-7892: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2014-9163P1HIGHCVSS 7.8KEV≥ 13.0, < 13.0.0.259≥ 14.0, ≤ 14.0.0.179+2 more2014-12-10
CVE-2014-9163 [HIGH] CWE-121 CVE-2014-9163: Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0. Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.
nvd
CVE-2017-11292P1HIGHCVSS 8.8KEV≤ 27.0.0.130≤ 27.0.0.1592017-10-22
CVE-2017-11292 [HIGH] CWE-843 CVE-2017-11292: Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, whic Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-5002P2HIGHCVSS 7.8KEV≤ 29.0.0.1712018-07-09
CVE-2018-5002 [HIGH] CWE-787 CVE-2018-5002: Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2013-0648P1HIGHCVSS 8.8KEVfixed in 10.3.183.67≥ 11.0, < 11.6.602.171+1 more2013-02-27
CVE-2013-0648 [HIGH] CVE-2013-0648: Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
nvd
CVE-2009-1862P2HIGHCVSS 7.8KEV≥ 9.0, ≤ 9.0.159.0≥ 10.0, ≤ 10.0.22.872009-07-23
CVE-2009-1862 [HIGH] CWE-787 CVE-2009-1862: Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exp
nvd
CVE-2013-0643P1HIGHCVSS 8.8KEVfixed in 10.3.183.67≥ 11.0, < 11.6.602.171+1 more2013-02-27
CVE-2013-0643 [HIGH] CWE-269 CVE-2013-0643: The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
nvd
CVE-2012-0767P2MEDIUMCVSS 6.1KEVfixed in 10.3.183.15≥ 11.0, < 11.1.102.62+2 more2012-02-16
CVE-2012-0767 [MEDIUM] CWE-79 CVE-2012-0767: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11 Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as expl
nvd
CVE-2012-2034P2HIGHCVSS 7.5KEV≤ 11.2.202.235≤ 11.1.115.8+1 more2012-06-09
CVE-2012-2034 [HIGH] CWE-119 CVE-2012-2034: Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 1 Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption)
nvd
CVE-2014-0569P1CRITICALCVSS 9.3ExploitedPoCRansomware≤ 11.2.202.406≤ 13.0.0.244+2 more2014-10-15
CVE-2014-0569 [CRITICAL] CWE-190 CVE-2014-0569: Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Wind Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2014-0515P1CRITICALCVSS 10.0ExploitedPoCRansomware≥ 11.0, < 11.2.202.346≥ 11.0, < 11.7.700.279+1 more2014-04-29
CVE-2014-0515 [CRITICAL] CWE-119 CVE-2014-0515: Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.20 Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
nvd
CVE-2014-0556P1CRITICALCVSS 10.0ExploitedPoCRansomware≤ 13.0.0.241v13.0.0.182+40 more2014-09-10
CVE-2014-0556 [CRITICAL] CWE-119 CVE-2014-0556: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.1 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbi
nvd
CVE-2015-3105P1CRITICALCVSS 10.0ExploitedPoCRansomware≤ 11.2.202.460≤ 13.0.0.289+17 more2015-06-10
CVE-2015-3105 [CRITICAL] CWE-119 CVE-2015-3105: Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and be
nvd
Adobe Flash Player vulnerabilities | cvebase