cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 29 of 55
CVE-2013-1379P3CRITICALCVSS 10.0≤ 10.3.183.68v6.0.21.0+163 more2013-04-10
CVE-2013-1379 [CRITICAL] CWE-119 CVE-2013-1379: Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 1 Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 do not properly initialize pointer arrays,
nvd
CVE-2015-7634P3CRITICALCVSS 10.0≤ 19.0.0.185≤ 11.2.202.5212015-10-15
CVE-2015-7634 [CRITICAL] CVE-2015-7634: Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vuln
nvd
CVE-2015-7627P3CRITICALCVSS 10.0≤ 11.2.202.521≤ 19.0.0.1852015-10-15
CVE-2015-7627 [CRITICAL] CVE-2015-7627: Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vuln
nvd
CVE-2015-7626P3CRITICALCVSS 10.0≤ 11.2.202.521≤ 19.0.0.1852015-10-14
CVE-2015-7626 [CRITICAL] CVE-2015-7626: Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vuln
nvd
CVE-2015-7625P3CRITICALCVSS 10.0≤ 19.0.0.185≤ 11.2.202.5212015-10-14
CVE-2015-7625 [CRITICAL] CWE-119 CVE-2015-7625: Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ
nvd
CVE-2011-4694P3CRITICALCVSS 9.3v11.1.102.552011-12-07
CVE-2011-4694 [CRITICAL] CVE-2011-4694: Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote at Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the second of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. How
nvd
CVE-2014-0580P3CRITICALCVSS 10.0≥ 13, < 13.0.0.259≥ 14, ≤ 14.0.0.179+2 more2014-12-10
CVE-2014-0580 [CRITICAL] CWE-264 CVE-2014-0580: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2014-0547P3CRITICALCVSS 10.0≤ 13.0.0.241v13.0.0.182+40 more2014-09-10
CVE-2014-0547 [CRITICAL] CWE-119 CVE-2014-0547: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of
nvd
CVE-2014-0555P3CRITICALCVSS 10.0≤ 11.2.202.400v11.2.202.223+40 more2014-09-10
CVE-2014-0555 [CRITICAL] CVE-2014-0555: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service
nvd
CVE-2014-0549P3CRITICALCVSS 10.0≤ 13.0.0.241v13.0.0.182+40 more2014-09-10
CVE-2014-0549 [CRITICAL] CVE-2014-0549: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service
nvd
CVE-2014-0551P3CRITICALCVSS 10.0≤ 13.0.0.241v13.0.0.182+40 more2014-09-10
CVE-2014-0551 [CRITICAL] CVE-2014-0551: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service
nvd
CVE-2014-0552P3CRITICALCVSS 10.0≤ 11.2.202.400v11.2.202.223+40 more2014-09-10
CVE-2014-0552 [CRITICAL] CVE-2014-0552: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service
nvd
CVE-2014-0550P3CRITICALCVSS 10.0≤ 11.2.202.400v11.2.202.223+40 more2014-09-10
CVE-2014-0550 [CRITICAL] CVE-2014-0550: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service
nvd
CVE-2010-2174P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2010-2174 [CRITICAL] CVE-2010-2174: Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, mi Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, related to an "invalid pointer vulnerability" and the newfunction (0x44) operator, a different vulnerability than CVE-2010-2173.
nvd
CVE-2010-2173P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2010-2173 [CRITICAL] CWE-119 CVE-2010-2173: Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, mi Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, related to an "invalid pointer vulnerability" and the newclass (0x58) operator, a different vulnerability than CVE-2010-2174.
nvd
CVE-2017-3099P3HIGHCVSS 8.8≤ 26.0.0.120≤ 26.0.0.1312017-07-17
CVE-2017-3099 [HIGH] CWE-787 CVE-2017-3099: Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-0339P3CRITICALCVSS 10.0≤ 11.2.202.442≤ 13.0.0.264+15 more2015-03-13
CVE-2015-0339 [CRITICAL] CVE-2015-0339: Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0333, and CVE-2015-0335.
nvd
CVE-2015-0333P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+15 more2015-03-13
CVE-2015-0333 [CRITICAL] CVE-2015-0333: Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0335, and CVE-2015-0339.
nvd
CVE-2015-7643P3CRITICALCVSS 9.3≤ 19.0.0.185≤ 11.2.202.5212015-10-15
CVE-2015-7643 [CRITICAL] CVE-2015-7643: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via a Video object with a crafted deblocking property, a
nvd
CVE-2015-7631P3CRITICALCVSS 9.3≤ 19.0.0.185≤ 11.2.202.5212015-10-15
CVE-2015-7631 [CRITICAL] CVE-2015-7631: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via a TextLine object with a crafted validity property, a
nvd