Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 41 of 55
CVE-2017-2937P3HIGHCVSS 8.8≤ 24.0.0.1862017-01-11
CVE-2017-2937 [HIGH] CWE-416 CVE-2017-2937: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class, when using class inheritance. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4286P3HIGHCVSS 8.8≤ 23.0.0.162≤ 11.2.202.635+1 more2016-10-13
CVE-2016-4286 [HIGH] CWE-284 CVE-2016-4286: Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2017-3003P3HIGHCVSS 8.8≤ 24.0.0.2212017-03-14
CVE-2017-3003 [HIGH] CWE-416 CVE-2017-3003: Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to an interaction between the privacy user interface and the ActionScript 2 Camera object. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4114P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4114 [HIGH] CVE-2016-4114: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4113P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4113 [HIGH] CVE-2016-4113: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4111P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4111 [HIGH] CVE-2016-4111: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4109P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4109 [HIGH] CVE-2016-4109: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4115P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4115 [HIGH] CVE-2016-4115: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4112P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4112 [HIGH] CVE-2016-4112: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1109P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1109 [HIGH] CVE-2016-1109: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1108P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1108 [HIGH] CVE-2016-1108: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1107P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1107 [HIGH] CVE-2016-1107: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4110P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4110 [HIGH] CVE-2016-4110: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1110P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1110 [HIGH] CVE-2016-1110: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-1097P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-1097 [HIGH] CVE-2016-1097: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2016-4116P3HIGHCVSS 7.5≤ 21.0.0.2132016-05-11
CVE-2016-4116 [HIGH] CVE-2016-4116: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash l
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
nvd
CVE-2017-3002P3HIGHCVSS 8.8≤ 24.0.0.2212017-03-14
CVE-2017-3002 [HIGH] CWE-416 CVE-2017-3002: Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability in the ActionScript2 TextField object related to the variable property. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2009-3793P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2009-3793 [CRITICAL] CWE-399 CVE-2009-3793: Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Ado
Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory consumption) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2008-4401P3CRITICALCVSS 10.0≤ 9.0.124.0v7.0+18 more2008-10-17
CVE-2008-4401 [CRITICAL] CWE-264 CVE-2008-4401: ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjun
ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified
nvd
CVE-2017-2999P3HIGHCVSS 8.8≤ 24.0.0.2212017-03-14
CVE-2017-2999 [HIGH] CWE-787 CVE-2017-2999: Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerabili
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK functionality related to hosting playback surface. Successful exploitation could lead to arbitrary code execution.
nvd