cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 34 of 55
CVE-2010-3642P3CRITICALCVSS 9.3≥ 9.0, < 9.0.289.0≥ 10.0.12.36, < 10.1.102.64+1 more2010-11-07
CVE-2010-3642 [CRITICAL] CVE-2010-3642: Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Wind Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3640, CVE-2010-3641, CVE-2010-3643, CVE-2010-
nvd
CVE-2010-3648P3CRITICALCVSS 9.3≥ 9.0, < 9.0.289.0≥ 10.0, < 10.1.102.64+1 more2010-11-07
CVE-2010-3648 [CRITICAL] CVE-2010-3648: Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Wind Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-
nvd
CVE-2010-3647P3CRITICALCVSS 9.3≥ 9.0, < 9.0.289.0≥ 10.0, < 10.1.102.64+1 more2010-11-07
CVE-2010-3647 [CRITICAL] CVE-2010-3647: Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Wind Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-
nvd
CVE-2010-3649P3CRITICALCVSS 9.3≥ 9.0, < 9.0.289.0≥ 10.0, < 10.1.102.64+1 more2010-11-07
CVE-2010-3649 [CRITICAL] CVE-2010-3649: Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Wind Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-
nvd
CVE-2015-8823P3HIGHCVSS 8.8≤ 19.0.0.245≤ 18.0.0.261+1 more2016-04-22
CVE-2015-8823 [HIGH] CVE-2015-8823: Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18. Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafted t
nvd
CVE-2016-1098P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1098 [HIGH] CVE-2016-1098: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1100P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1100 [HIGH] CVE-2016-1100: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1099P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1099 [HIGH] CVE-2016-1099: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2017-2936P3HIGHCVSS 8.8≤ 24.0.0.1862017-01-11
CVE-2017-2936 [HIGH] CWE-416 CVE-2017-2936: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3071P3HIGHCVSS 8.8≤ 25.0.0.1482017-05-09
CVE-2017-3071 [HIGH] CWE-416 CVE-2017-3071: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2993P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2993 [HIGH] CWE-416 CVE-2017-2993: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability related to event handlers. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2982P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2982 [HIGH] CWE-416 CVE-2017-2982: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in a routine related to player shutdown. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7880P3HIGHCVSS 8.8≤ 23.0.0.207≤ 11.2.202.6442016-12-15
CVE-2016-7880 [HIGH] CWE-416 CVE-2016-7880: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability when setting the length property of an array object. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7881P3HIGHCVSS 8.8≤ 23.0.0.207≤ 11.2.202.6442016-12-15
CVE-2016-7881 [HIGH] CWE-416 CVE-2016-7881: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class when handling conversion to an object. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-7845P3HIGHCVSS 8.8≤ 32.0.0.1922019-06-12
CVE-2019-7845 [HIGH] CWE-416 CVE-2019-7845: Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earli Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-8460P3HIGHCVSS 8.8≤ 18.0.0.268v19.0.0.185+6 more2015-12-28
CVE-2015-8460 [HIGH] CVE-2015-8460: Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and bef Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different
nvd
CVE-2017-3001P3HIGHCVSS 8.8≤ 24.0.0.2212017-03-14
CVE-2017-3001 [HIGH] CWE-416 CVE-2017-3001: Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to garbage collection in the ActionScript 2 VM. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2925P3HIGHCVSS 8.8≤ 24.0.0.1862017-01-11
CVE-2017-2925 [HIGH] CWE-787 CVE-2017-2925: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability in the JPEG XR codec. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2928P3HIGHCVSS 8.8≤ 24.0.0.1862017-01-11
CVE-2017-2928 [HIGH] CWE-787 CVE-2017-2928: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to setting visual mode effects. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3070P3HIGHCVSS 8.8≤ 25.0.0.1482017-05-09
CVE-2017-3070 [HIGH] CWE-787 CVE-2017-3070: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the ConvolutionFilter class. Successful exploitation could lead to arbitrary code execution.
nvd
Adobe Flash Player vulnerabilities | cvebase