cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 3 of 55
CVE-2015-0359P1CRITICALCVSS 10.0ExploitedPoC≤ 13.0.0.264v14.0.0.125+15 more2015-04-14
CVE-2015-0359 [CRITICAL] CVE-2015-0359: Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0. Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
nvd
CVE-2015-5560P1CRITICALCVSS 10.0ExploitedPoC≤ 11.2.202.491≤ 18.0.0.2092015-08-14
CVE-2015-5560 [CRITICAL] CWE-189 CVE-2015-5560: Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2013-5331P1CRITICALCVSS 9.3ExploitedPoC≥ 11.0, < 11.7.700.257≥ 11.8, < 11.8.800.175+2 more2013-12-11
CVE-2013-5331 [CRITICAL] CWE-94 CVE-2013-5331: Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "
nvd
CVE-2015-3090P1CRITICALCVSS 10.0ExploitedPoC≤ 13.0.0.264v14.0.0.125+16 more2015-05-13
CVE-2015-3090 [CRITICAL] CVE-2015-3090: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a d
nvd
CVE-2012-0779P1CRITICALCVSS 9.3ExploitedPoC≥ 10.3, < 10.3.183.19≥ 11.2, ≤ 11.2.202.233+2 more2012-05-04
CVE-2012-0779 [CRITICAL] CVE-2012-0779: Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.
nvd
CVE-2013-0634P1CRITICALCVSS 9.3ExploitedPoCRansomware≥ 10.3, < 10.3.183.51≥ 11.5, < 11.5.502.149+3 more2013-02-08
CVE-2013-0634 [CRITICAL] CWE-119 CVE-2013-0634: Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 1 Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF conte
nvd
CVE-2015-0336P1CRITICALCVSS 9.3ExploitedPoC≤ 13.0.0.264v14.0.0.125+15 more2015-03-13
CVE-2015-0336 [CRITICAL] CVE-2015-0336: Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.
nvd
CVE-2011-2110P2CRITICALCVSS 10.0ExploitedPoC≤ 10.3.181.23v6.0.21.0+87 more2011-06-16
CVE-2011-2110 [CRITICAL] CWE-119 CVE-2011-2110: Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.
nvd
CVE-2011-2140P2CRITICALCVSS 10.0ExploitedPoC≤ 10.3.181.36v6.0.21.0+90 more2011-08-10
CVE-2011-2140 [CRITICAL] CVE-2011-2140: Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135,
nvd
CVE-2010-3654P2CRITICALCVSS 9.3ExploitedPoC≤ 10.1.85.3v6.0.21.0+56 more2010-10-29
CVE-2010-3654 [CRITICAL] CWE-119 CVE-2010-3654: Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Sol Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applica
nvd
CVE-2013-0633P2CRITICALCVSS 9.3ExploitedPoC≥ 10.3, < 10.3.183.51≥ 11.5, < 11.5.502.149+3 more2013-02-08
CVE-2013-0633 [CRITICAL] CWE-119 CVE-2013-0633: Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild i
nvd
CVE-2015-3104P2CRITICALCVSS 10.0ExploitedPoC≤ 11.2.202.460≤ 13.0.0.289+17 more2015-06-10
CVE-2015-3104 [CRITICAL] CWE-189 CVE-2015-3104: Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.14
nvd
CVE-2007-0071P2CRITICALCVSS 9.3Exploited≥ 8.0, ≤ 8.0.39.0≥ 9.0, ≤ 9.0.115.02008-04-09
CVE-2007-0071 [CRITICAL] CWE-189 CVE-2007-0071: Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remot Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.
nvd
CVE-2010-2884P2CRITICALCVSS 9.3Exploited≤ 10.1.82.76v7.0+47 more2010-09-15
CVE-2010-2884 [CRITICAL] CVE-2010-2884: Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unsp
nvd
CVE-2014-0498P2CRITICALCVSS 10.0Exploited≥ 11.0, < 11.7.700.269≥ 11.8, < 11.8.800.175+2 more2014-02-21
CVE-2014-0498 [CRITICAL] CWE-119 CVE-2014-0498: Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x befo Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified v
nvd
CVE-2015-3133P2CRITICALCVSS 10.0ExploitedRansomware≤ 11.2.202.468≤ 13.0.0.289+20 more2015-07-09
CVE-2015-3133 [CRITICAL] CVE-2015-3133: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a d
nvd
CVE-2015-8446P2CRITICALCVSS 9.3ExploitedRansomware≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8446 [CRITICAL] CVE-2015-8446: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.2 Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled
nvd
CVE-2012-4167P2CRITICALCVSS 10.0Exploited≥ 10.3, < 10.3.183.23≥ 11.4, < 11.4.402.265+3 more2012-08-21
CVE-2012-4167 [CRITICAL] CWE-189 CVE-2012-4167: Integer overflow in Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows an Integer overflow in Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allows attackers to execute arbitr
nvd
CVE-2011-2444P2MEDIUMCVSS 4.3Exploited≤ 10.3.183.7v6.0.21.0+94 more2011-09-22
CVE-2011-2444 [MEDIUM] CWE-79 CVE-2011-2444: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.
nvd
CVE-2014-0564P2CRITICALCVSS 10.0Exploited≤ 11.2.202.406≤ 13.0.0.244+2 more2014-10-15
CVE-2014-0564 [CRITICAL] CVE-2014-0564: Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and bef Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe
nvd
Adobe Flash Player vulnerabilities | cvebase