Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 4 of 55
CVE-2011-2107P2MEDIUMCVSS 4.3Exploited≤ 10.3.181.16v6.0.21.0+86 more2011-06-09
CVE-2011-2107 [MEDIUM] CWE-79 CVE-2011-2107: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."
nvd
CVE-2013-5330P2CRITICALCVSS 10.0Exploited≥ 11.0, < 11.7.700.252≥ 11.8, < 11.8.800.175+2 more2013-11-13
CVE-2013-5330 [CRITICAL] CVE-2013-5330: Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto
nvd
CVE-2015-0349P2CRITICALCVSS 10.0Exploited≤ 13.0.0.264v14.0.0.125+15 more2015-04-14
CVE-2015-0349 [CRITICAL] CVE-2015-0349: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0351, CVE-2015-0358, and CVE-2015-3039.
nvd
CVE-2011-0627P2HIGHCVSS 8.8Exploited≤ 10.2.159.1v6.0.21.0+82 more2011-05-13
CVE-2011-0627 [HIGH] CWE-20 CVE-2011-0627: Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.2
Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
nvd
CVE-2012-0773P2CRITICALCVSS 9.3Exploitedfixed in 10.3.183.18≥ 11.0, < 11.2.202.228+2 more2012-03-28
CVE-2012-0773 [CRITICAL] CWE-787 CVE-2012-0773: The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows
The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (m
nvd
CVE-2011-0559P2CRITICALCVSS 9.3Exploited≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0559 [CRITICAL] CWE-119 CVE-2011-0559: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted parameters to an unspecified ActionScript method that cause a parameter to be used as an object pointer, a different vulnerability than CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573
nvd
CVE-2015-3087P2CRITICALCVSS 10.0PoC≤ 11.2.202.475≤ 13.0.0.264+16 more2015-05-13
CVE-2015-3087 [CRITICAL] CWE-189 CVE-2015-3087: Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-0318P2CRITICALCVSS 10.0PoC≤ 13.0.0.264v14.0.0.125+14 more2015-02-06
CVE-2015-0318 [CRITICAL] CVE-2015-0318: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0321, CVE-2015-0329, and CVE-2015-0330.
nvd
CVE-2014-8440P2CRITICALCVSS 10.0PoC≥ 13.0, < 13.0.0.252≥ 14.0, ≤ 14.0.0.179+2 more2014-11-11
CVE-2014-8440 [CRITICAL] CVE-2014-8440: Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and bef
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe
nvd
CVE-2011-0618P2CRITICALCVSS 9.3Exploited≤ 10.2.159.1v6.0.21.0+82 more2011-05-13
CVE-2011-0618 [CRITICAL] CWE-189 CVE-2011-0618: Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris a
Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-3088P2CRITICALCVSS 10.0PoC≤ 11.2.202.475≤ 13.0.0.264+16 more2015-05-13
CVE-2015-3088 [CRITICAL] CWE-119 CVE-2015-3088: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-3080P2CRITICALCVSS 10.0PoC≤ 13.0.0.264v14.0.0.125+16 more2015-05-13
CVE-2015-3080 [CRITICAL] CVE-2015-3080: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-5132P2CRITICALCVSS 10.0PoC≤ 18.0.0.209≤ 11.2.202.4912015-08-14
CVE-2015-5132 [CRITICAL] CVE-2015-5132: Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5133.
nvd
CVE-2015-5131P2CRITICALCVSS 10.0PoC≤ 18.0.0.209≤ 11.2.202.4912015-08-14
CVE-2015-5131 [CRITICAL] CWE-119 CVE-2015-5131: Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5132 and CVE-2015-5133.
nvd
CVE-2015-5133P2CRITICALCVSS 10.0PoC≤ 11.2.202.491≤ 18.0.0.2092015-08-14
CVE-2015-5133 [CRITICAL] CVE-2015-5133: Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5132.
nvd
CVE-2017-11282P2CRITICALCVSS 9.8PoC≤ 26.0.0.1512017-12-01
CVE-2017-11282 [CRITICAL] CWE-119 CVE-2017-11282: Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Succes
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
nvd
CVE-2015-5574P2CRITICALCVSS 10.0PoC≤ 13.0.0.289v14.0.0.125+24 more2015-09-22
CVE-2015-5574 [CRITICAL] CVE-2015-5574: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on W
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than C
nvd
CVE-2017-11281P2CRITICALCVSS 9.8PoC≤ 26.0.0.1512017-12-01
CVE-2017-11281 [CRITICAL] CWE-119 CVE-2017-11281: Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function.
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
nvd
CVE-2016-0971P2HIGHCVSS 8.8PoC≤ 11.2.202.559≤ 18.0.0.326+2 more2016-02-10
CVE-2016-0971 [HIGH] CWE-787 CVE-2016-0971: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.3
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-3106P2CRITICALCVSS 10.0PoC≤ 11.2.202.460≤ 13.0.0.289+17 more2015-06-10
CVE-2015-3106 [CRITICAL] CVE-2015-3106: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0
nvd