cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 40 of 55
CVE-2013-3330P3CRITICALCVSS 10.0fixed in 10.3.183.86≥ 11.0, < 11.7.700.202+3 more2013-05-16
CVE-2013-3330 [CRITICAL] CVE-2013-3330: Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 1 Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler before 3.7.0.1860 allow attackers to execute arbitrary code or cause
nvd
CVE-2013-2728P3CRITICALCVSS 10.0fixed in 10.3.183.86≥ 11.0, < 11.7.700.202+3 more2013-05-16
CVE-2013-2728 [CRITICAL] CWE-119 CVE-2013-2728: Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 1 Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler before 3.7.0.1860 allow attackers to execute arbitrary code o
nvd
CVE-2015-8408P3CRITICALCVSS 10.0≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8408 [CRITICAL] CVE-2015-8408: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe
nvd
CVE-2015-8060P3CRITICALCVSS 10.0≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8060 [CRITICAL] CVE-2015-8060: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe
nvd
CVE-2015-8047P3CRITICALCVSS 10.0≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8047 [CRITICAL] CVE-2015-8047: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe
nvd
CVE-2015-8045P3CRITICALCVSS 10.0≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8045 [CRITICAL] CWE-119 CVE-2015-8045: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors,
nvd
CVE-2010-2188P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2010-2188 [CRITICAL] CVE-2010-2188: Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, al Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-21
nvd
CVE-2011-0558P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0558 [CRITICAL] CWE-189 CVE-2011-0558: Integer overflow in Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code Integer overflow in Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code via a large array length value in the ActionScript method of the Function class.
nvd
CVE-2015-8442P3CRITICALCVSS 9.3≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8442 [CRITICAL] CVE-2015-8442: Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18. Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a cra
nvd
CVE-2015-8437P3CRITICALCVSS 9.3≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8437 [CRITICAL] CVE-2015-8437: Use-after-free vulnerability in the Selection object implementation in Adobe Flash Player before 18. Use-after-free vulnerability in the Selection object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a cra
nvd
CVE-2015-8447P3CRITICALCVSS 9.3≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8447 [CRITICAL] CVE-2015-8447: Use-after-free vulnerability in the Color object implementation in Adobe Flash Player before 18.0.0. Use-after-free vulnerability in the Color object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafted s
nvd
CVE-2015-8448P3CRITICALCVSS 9.3≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8448 [CRITICAL] CVE-2015-8448: Use-after-free vulnerability in the DisplacementMapFilter object implementation in Adobe Flash Playe Use-after-free vulnerability in the DisplacementMapFilter object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary co
nvd
CVE-2015-8449P3CRITICALCVSS 9.3≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8449 [CRITICAL] CVE-2015-8449: Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18. Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a cra
nvd
CVE-2015-8436P3CRITICALCVSS 9.3≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8436 [CRITICAL] CVE-2015-8436: Use-after-free vulnerability in the PrintJob object implementation in Adobe Flash Player before 18.0 Use-after-free vulnerability in the PrintJob object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafte
nvd
CVE-2016-0959P3CRITICALCVSS 9.8≤ 20.0.0.235≤ 20.0.0.2282017-06-27
CVE-2016-0959 [CRITICAL] CWE-416 CVE-2016-0959: Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Pl Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet Explorer 10 and 11 before 20.0.0
nvd
CVE-2014-0587P3CRITICALCVSS 10.0≥ 13.0, < 13.0.0.259≥ 14.0, ≤ 16.0.0.235+1 more2014-12-10
CVE-2014-0587 [CRITICAL] CWE-94 CVE-2014-0587: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-9164.
nvd
CVE-2011-0628P3CRITICALCVSS 9.3≤ 10.2.159.1v6.0.21.0+82 more2011-05-31
CVE-2011-0628 [CRITICAL] CWE-189 CVE-2011-0628: Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris a Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code via ActionScript that improperly handles a long array object.
nvd
CVE-2009-3798P3CRITICALCVSS 9.3≤ 10.0.32.18v7.0+36 more2009-12-10
CVE-2009-3798 [CRITICAL] CWE-399 CVE-2009-3798: Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arb Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
nvd
CVE-2014-0535P3HIGHCVSS 7.5≤ 11.2.202.359v11.2.202.223+29 more2014-06-11
CVE-2014-0535 [HIGH] CVE-2014-0535: Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0534.
nvd
CVE-2015-8822P3HIGHCVSS 8.8≤ 11.2.202.548≤ 18.0.0.261+1 more2016-03-04
CVE-2015-8822 [HIGH] CVE-2015-8822: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafted MPEG-4 data, a different vulnerability t
nvd
Adobe Flash Player vulnerabilities | cvebase