cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 28 of 55
CVE-2016-1005P3HIGHCVSS 8.8≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-1005 [HIGH] CVE-2016-1005: Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and memory corrup
nvd
CVE-2016-6987P3HIGHCVSS 8.8≤ 23.0.0.162≤ 18.0.0.375+1 more2016-10-13
CVE-2016-6987 [HIGH] CVE-2016-6987: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-6981.
nvd
CVE-2016-7874P3HIGHCVSS 8.8≤ 23.0.0.207≤ 11.2.202.6442016-12-15
CVE-2016-7874 [HIGH] CWE-787 CVE-2016-7874: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable mem Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the NetConnection class when handling the proxy types. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-0992P3HIGHCVSS 8.8≤ 20.0.0.306≤ 11.2.202.5692016-03-12
CVE-2016-0992 [HIGH] CVE-2016-0992: Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe
nvd
CVE-2010-3976P3CRITICALCVSS 9.3≤ 9.0.277.0v9.0.16+39 more2010-10-19
CVE-2010-3976 [CRITICAL] CVE-2010-3976: Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102. Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Flash Player.
nvd
CVE-2016-4280P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4280 [HIGH] CVE-2016-4280: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4281, CVE-2016-4282, CVE-2016-4
nvd
CVE-2016-6924P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-6924 [HIGH] CVE-2016-6924: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4
nvd
CVE-2016-4281P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4281 [HIGH] CVE-2016-4281: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4282, CVE-2016-4
nvd
CVE-2016-4276P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4276 [HIGH] CVE-2016-4276: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CVE-2016-4
nvd
CVE-2016-6922P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-6922 [HIGH] CVE-2016-6922: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4
nvd
CVE-2016-4283P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4283 [HIGH] CVE-2016-4283: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4
nvd
CVE-2016-4282P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4282 [HIGH] CVE-2016-4282: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4
nvd
CVE-2016-4284P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4284 [HIGH] CVE-2016-4284: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4
nvd
CVE-2016-4274P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4274 [HIGH] CWE-787 CVE-2016-4274: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CV
nvd
CVE-2016-4285P3HIGHCVSS 8.8≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4285 [HIGH] CVE-2016-4285: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4
nvd
CVE-2014-0491P3CRITICALCVSS 10.0≥ 11.0, < 11.7.700.260≥ 11.8, < 11.8.800.175+2 more2014-01-15
CVE-2014-0491 [CRITICAL] CWE-264 CVE-2014-0491: Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to bypass unspecified protection mechanisms via unknown vectors.
nvd
CVE-2008-4473P3CRITICALCVSS 9.3vcs3vmx_20042008-10-17
CVE-2008-4473 [CRITICAL] CWE-119 CVE-2008-4473: Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 al Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.
nvd
CVE-2018-12825P3CRITICALCVSS 9.8≤ 30.0.0.1542018-08-29
CVE-2018-12825 [CRITICAL] CVE-2018-12825: Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitat Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass.
nvd
CVE-2010-0187P4MEDIUMCVSS 4.3PoC≤ 10.0.42.34v6.0.21.0+45 more2010-02-15
CVE-2010-0187 [MEDIUM] CWE-94 CVE-2010-0187: Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.
nvd
CVE-2015-7629P3CRITICALCVSS 9.3≤ 11.2.202.521≤ 19.0.0.1852015-10-15
CVE-2015-7629 [CRITICAL] CVE-2015-7629: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via a TextFormat object with a crafted tabStops property,
nvd
Adobe Flash Player vulnerabilities | cvebase