cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 43 of 55
CVE-2016-4123P3HIGHCVSS 8.8≤ 11.2.202.621≤ 18.0.0.352+1 more2016-06-16
CVE-2016-4123 [HIGH] CWE-787 CVE-2016-4123: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4146P3HIGHCVSS 8.8≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4146 [HIGH] CVE-2016-4146: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4144P3HIGHCVSS 8.8≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4144 [HIGH] CVE-2016-4144: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4128P3HIGHCVSS 8.8≤ 11.2.202.621≤ 18.0.0.352+1 more2016-06-16
CVE-2016-4128 [HIGH] CWE-787 CVE-2016-4128: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4133P3HIGHCVSS 8.8≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4133 [HIGH] CVE-2016-4133: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4142P3HIGHCVSS 8.8≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4142 [HIGH] CVE-2016-4142: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2015-5566P3CRITICALCVSS 10.0≤ 11.2.202.491≤ 18.0.0.2092015-08-24
CVE-2015-5566 [CRITICAL] CVE-2015-5566: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130,
nvd
CVE-2012-0768P3CRITICALCVSS 10.0≤ 10.3.183.15v2+109 more2012-03-05
CVE-2012-0768 [CRITICAL] CWE-399 CVE-2012-0768: The Matrix3D component in Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windo The Matrix3D component in Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2450P3CRITICALCVSS 10.0≥ 10.0, < 10.3.183.11≥ 11.0, < 11.1.102.55+1 more2011-11-11
CVE-2011-2450 [CRITICAL] CWE-119 CVE-2011-2450: Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and S Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2015-0301P3CRITICALCVSS 10.0v11.2.202.425≤ 13.0.0.259+14 more2015-01-13
CVE-2015-0301 [CRITICAL] CWE-20 CVE-2015-0301: Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 do not properly validate files, which has unspecified impac
nvd
CVE-2011-2424P3CRITICALCVSS 9.3≤ 10.3.181.36v6.0.21.0+90 more2011-08-15
CVE-2011-2424 [CRITICAL] CWE-119 CVE-2011-2424: Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted SWF file, as demonstrated by "about 400 un
nvd
CVE-2010-2171P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2010-2171 [CRITICAL] CVE-2010-2171: Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, al Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors related to SWF files, decompression of embedded JPEG image data, and the DefineBits and other unspecified tags, a different vulnerability than CVE-2
nvd
CVE-2014-9162P3CRITICALCVSS 10.0≥ 13.0, < 13.0.0.259≥ 14.0, ≤ 14.0.0.179+2 more2014-12-10
CVE-2014-9162 [CRITICAL] CWE-200 CVE-2014-9162: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2011-2427P3CRITICALCVSS 9.3≤ 10.3.183.7v6.0.21.0+94 more2011-09-22
CVE-2011-2427 [CRITICAL] CWE-119 CVE-2011-2427: Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Playe Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
nvd
CVE-2015-7656P3CRITICALCVSS 9.3≤ 18.0.0.255v19.0.0.185+3 more2015-11-11
CVE-2015-7656 [CRITICAL] CVE-2015-7656: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted actionImplementsOp arguments, a different vul
nvd
CVE-2015-7660P3CRITICALCVSS 9.3≤ 18.0.0.255v19.0.0.185+3 more2015-11-11
CVE-2015-7660 [CRITICAL] CVE-2015-7660: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted setMask arguments, a different vulnerability
nvd
CVE-2015-7651P3CRITICALCVSS 9.3≤ 11.2.202.540≤ 18.0.0.255+3 more2015-11-11
CVE-2015-7651 [CRITICAL] CVE-2015-7651: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted DefineFunction atoms, a different vulnerabili
nvd
CVE-2015-7658P3CRITICALCVSS 9.3≤ 11.2.202.540≤ 18.0.0.255+3 more2015-11-11
CVE-2015-7658 [CRITICAL] CVE-2015-7658: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted actionInstanceOf arguments, a different vulne
nvd
CVE-2015-8042P3CRITICALCVSS 9.3≤ 18.0.0.255v19.0.0.185+3 more2015-11-11
CVE-2015-8042 [CRITICAL] CVE-2015-8042: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via a crafted loadSound call, a different vulnerability t
nvd
CVE-2015-7657P3CRITICALCVSS 9.3≤ 18.0.0.255v19.0.0.185+3 more2015-11-11
CVE-2015-7657 [CRITICAL] CVE-2015-7657: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted actionCallMethod arguments, a different vulne
nvd