Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 44 of 55
CVE-2015-7655P3CRITICALCVSS 9.3≤ 11.2.202.540≤ 18.0.0.255+3 more2015-11-11
CVE-2015-7655 [CRITICAL] CVE-2015-7655: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted actionExtends arguments, a different vulnerab
nvd
CVE-2015-7653P3CRITICALCVSS 9.3≤ 11.2.202.540≤ 18.0.0.255+3 more2015-11-11
CVE-2015-7653 [CRITICAL] CVE-2015-7653: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted globalToLocal arguments, a different vulnerab
nvd
CVE-2015-7654P3CRITICALCVSS 9.3≤ 11.2.202.540≤ 18.0.0.255+3 more2015-11-11
CVE-2015-7654 [CRITICAL] CVE-2015-7654: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted attachSound arguments, a different vulnerabil
nvd
CVE-2015-7661P3CRITICALCVSS 9.3≤ 18.0.0.255v19.0.0.185+3 more2015-11-11
CVE-2015-7661 [CRITICAL] CVE-2015-7661: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via a crafted getBounds call, a different vulnerability t
nvd
CVE-2015-8656P3HIGHCVSS 8.8≤ 11.2.202.548≤ 18.0.0.261+1 more2016-03-04
CVE-2015-8656 [HIGH] CVE-2015-8656: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef
Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via crafted M
nvd
CVE-2015-8657P3HIGHCVSS 8.8≤ 11.2.202.548≤ 18.0.0.261+1 more2016-03-04
CVE-2015-8657 [HIGH] CVE-2015-8657: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef
Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via crafted M
nvd
CVE-2015-8820P3HIGHCVSS 8.8≤ 11.2.202.548≤ 18.0.0.261+1 more2016-03-04
CVE-2015-8820 [HIGH] CVE-2015-8820: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef
Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via crafted M
nvd
CVE-2015-8049P3CRITICALCVSS 9.3≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8049 [CRITICAL] CVE-2015-8049: Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.
Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a cra
nvd
CVE-2015-8050P3CRITICALCVSS 9.3≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8050 [CRITICAL] CVE-2015-8050: Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18.
Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a cra
nvd
CVE-2015-8058P3CRITICALCVSS 9.3≤ 18.0.0.261v19.0.0.185+4 more2015-12-10
CVE-2015-8058 [CRITICAL] CVE-2015-8058: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2014-9164P3CRITICALCVSS 10.0≥ 13.0, < 13.0.0.259≥ 14.0, ≤ 14.0.0.179+2 more2014-12-10
CVE-2014-9164 [CRITICAL] CVE-2014-9164: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and
Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0587.
nvd
CVE-2010-0378P3HIGHCVSS 8.8v6.0.792010-01-21
CVE-2010-0378 [HIGH] CWE-416 CVE-2010-0378: Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP
Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accessed by a script, leading to memory corruption, aka a "Movie Unloading Vulnerability."
nvd
CVE-2014-0583P3HIGHCVSS 7.5≥ 13.0, < 13.0.0.252≥ 14.0, ≤ 14.0.0.179+2 more2014-11-11
CVE-2014-0583 [HIGH] CWE-119 CVE-2014-0583: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.2
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to complete a transition from Low Integrity to Medium Integrity via unsp
nvd
CVE-2014-0541P3CRITICALCVSS 10.0≤ 13.0.0.231v13.0.0.182+35 more2014-08-12
CVE-2014-0541 [CRITICAL] CWE-264 CVE-2014-0541: Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 allow attackers to bypass intended access restrictions via unspecified
nvd
CVE-2018-4871P3HIGHCVSS 7.5≤ 28.0.0.1262018-01-09
CVE-2018-4871 [HIGH] CWE-125 CVE-2018-4871: An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerabili
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensi
nvd
CVE-2014-0557P3CRITICALCVSS 10.0≤ 11.2.202.400v11.2.202.223+40 more2014-09-10
CVE-2014-0557 [CRITICAL] CWE-264 CVE-2014-0557: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do not properly restrict discovery of memory addresses, which
nvd
CVE-2010-2160P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2010-2160 [CRITICAL] CWE-119 CVE-2010-2160: Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, al
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an invalid offset in an unspecified undocumented opcode in ActionScript Virtual Machine 2, related to getouterscope, a different vulnerability than
nvd
CVE-2010-2162P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2010-2162 [CRITICAL] CWE-119 CVE-2010-2162: Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, al
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors related to improper length calculation and the (1) STSC, (2) STSZ, and (3) STCO atoms.
nvd
CVE-2012-0751P3CRITICALCVSS 10.0fixed in 10.3.183.15≥ 11.0, < 11.1.102.622012-02-16
CVE-2012-0751 [CRITICAL] CWE-787 CVE-2012-0751: The ActiveX control in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows
The ActiveX control in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-8650P3HIGHCVSS 8.8≤ 18.0.0.268v19.0.0.185+6 more2015-12-28
CVE-2015-8650 [HIGH] CVE-2015-8650: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability t
nvd