Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 47 of 55
CVE-2012-0755P3CRITICALCVSS 9.3fixed in 10.3.183.15≥ 11.0, < 11.1.102.62+2 more2012-02-16
CVE-2012-0755 [CRITICAL] CVE-2012-0755: Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and S
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0756.
nvd
CVE-2018-15978P3HIGHCVSS 7.5≤ 31.0.0.1222018-11-29
CVE-2018-15978 [HIGH] CWE-125 CVE-2018-15978: Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful ex
Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-12826P3HIGHCVSS 7.5≤ 30.0.0.1542018-08-29
CVE-2018-12826 [HIGH] CWE-125 CVE-2018-12826: Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful explo
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-5008P3HIGHCVSS 7.5≤ 30.0.0.1132018-07-20
CVE-2018-5008 [HIGH] CWE-125 CVE-2018-5008: Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Success
Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2014-0492P3CRITICALCVSS 10.0≥ 11.0, < 11.7.700.260≥ 11.8, < 11.8.800.175+2 more2014-01-15
CVE-2014-0492 [CRITICAL] CWE-264 CVE-2014-0492: Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS
Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."
nvd
CVE-2012-5673P3CRITICALCVSS 10.0≥ 10.3, < 10.3.183.29≥ 11.4, < 11.4.402.287+3 more2012-11-13
CVE-2012-5673 [CRITICAL] CVE-2012-5673: Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on W
Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 has unknown impact and attack vec
nvd
CVE-2010-3975P3CRITICALCVSS 9.3v9.02010-10-19
CVE-2010-3975 [CRITICAL] CVE-2010-3975: Untrusted search path vulnerability in Adobe Flash Player 9 allows local users, and possibly remote
Untrusted search path vulnerability in Adobe Flash Player 9 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.dll that is located in the same folder as a file that is processed by Flash.
nvd
CVE-2011-0560P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0560 [CRITICAL] CVE-2011-0560: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.
nvd
CVE-2011-0561P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0561 [CRITICAL] CVE-2011-0561: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.
nvd
CVE-2011-0573P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0573 [CRITICAL] CVE-2011-0573: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0574, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.
nvd
CVE-2011-0571P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0571 [CRITICAL] CVE-2011-0571: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.
nvd
CVE-2011-0608P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0608 [CRITICAL] CVE-2011-0608: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, and CVE-2011-0607.
nvd
CVE-2011-0572P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0572 [CRITICAL] CVE-2011-0572: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.
nvd
CVE-2011-0607P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0607 [CRITICAL] CVE-2011-0607: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, and CVE-2011-0608.
nvd
CVE-2011-0574P3CRITICALCVSS 9.3≤ 10.2.152v6.0.21.0+73 more2011-02-10
CVE-2011-0574 [CRITICAL] CVE-2011-0574: Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial o
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.
nvd
CVE-2012-0753P3CRITICALCVSS 9.3fixed in 10.3.183.15≥ 11.0, < 11.1.102.62+2 more2012-02-16
CVE-2012-0753 [CRITICAL] CWE-787 CVE-2012-0753: Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and S
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted MP4 data.
nvd
CVE-2012-2037P3CRITICALCVSS 9.3≤ 11.2.202.235≤ 11.1.115.8+1 more2012-06-09
CVE-2012-2037 [CRITICAL] CVE-2012-2037: Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 1
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via
nvd
CVE-2011-2458P3CRITICALCVSS 9.3≥ 10.0, < 10.3.183.11≥ 11.0, < 11.1.102.55+1 more2011-11-11
CVE-2011-2458 [CRITICAL] CWE-264 CVE-2011-2458: Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and S
Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, when Internet Explorer is used, allows remote attackers to bypass the cross-domain policy via a crafted web site.
nvd
CVE-2017-3058P3HIGHCVSS 7.8≤ 25.0.0.1272017-04-12
CVE-2017-3058 [HIGH] CWE-416 CVE-2017-3058: Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the sound class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2014-0534P3HIGHCVSS 7.5≤ 13.0.0.214v13.0.0.182+29 more2014-06-11
CVE-2014-0534 [HIGH] CWE-264 CVE-2014-0534: Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.
Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0535.
nvd