cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 48 of 55
CVE-2009-1866P3CRITICALCVSS 9.3≤ 10.0.22.87v7.0+29 more2009-07-31
CVE-2009-1866 [CRITICAL] CWE-119 CVE-2009-1866: Stack-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and A Stack-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2014-0548P3HIGHCVSS 7.5≤ 13.0.0.241v13.0.0.182+40 more2014-09-10
CVE-2014-0548 [HIGH] CWE-264 CVE-2014-0548: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and bef Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow remote attackers to bypass the Same Origin Policy via unspec
nvd
CVE-2015-7662P3HIGHCVSS 7.8≤ 11.2.202.540≤ 18.0.0.255+3 more2015-11-11
CVE-2015-7662 [HIGH] CWE-264 CVE-2015-7662: Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allow remote attackers to bypass intended access restrictions and write to files via unspecified vectors.
nvd
CVE-2014-0542P3CRITICALCVSS 10.0≤ 13.0.0.231v13.0.0.182+35 more2014-08-12
CVE-2014-0542 [CRITICAL] CVE-2014-0542: Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers
nvd
CVE-2014-0543P3CRITICALCVSS 10.0≤ 13.0.0.231v13.0.0.182+35 more2014-08-12
CVE-2014-0543 [CRITICAL] CVE-2014-0543: Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers
nvd
CVE-2014-0540P3CRITICALCVSS 10.0≤ 13.0.0.231v13.0.0.182+35 more2014-08-12
CVE-2014-0540 [CRITICAL] CWE-264 CVE-2014-0540: Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows at
nvd
CVE-2014-0545P3CRITICALCVSS 10.0≤ 13.0.0.231v13.0.0.182+35 more2014-08-12
CVE-2014-0545 [CRITICAL] CVE-2014-0545: Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers
nvd
CVE-2014-0544P3CRITICALCVSS 10.0≤ 13.0.0.231v13.0.0.182+35 more2014-08-12
CVE-2014-0544 [CRITICAL] CVE-2014-0544: Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers
nvd
CVE-2011-2428P3CRITICALCVSS 9.3≤ 10.3.183.7v6.0.21.0+94 more2011-09-22
CVE-2011-2428 [CRITICAL] CWE-20 CVE-2011-2428: Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186. Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service (browser crash) via unspecified vectors, related to a "logic error issue."
nvd
CVE-2009-3800P3CRITICALCVSS 9.3≤ 10.0.32.18v7.0+36 more2009-12-10
CVE-2009-3800 [CRITICAL] CVE-2009-3800: Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1. Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-4429P3CRITICALCVSS 10.0≤ 11.2.202.468≤ 13.0.0.289+20 more2015-07-09
CVE-2015-4429 [CRITICAL] CVE-2015-4429: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via u
nvd
CVE-2007-6244P4MEDIUMCVSS 4.3PoCv8.0v9.02007-12-20
CVE-2007-6244 [MEDIUM] CWE-79 CVE-2007-6244: Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.
nvd
CVE-2014-0516P3HIGHCVSS 7.5≥ 13.0, < 13.0.0.214≥ 11.0, < 11.2.202.3592014-05-14
CVE-2014-0516 [HIGH] CWE-264 CVE-2014-0516: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2010-3636P3CRITICALCVSS 9.3≥ 9.0, < 9.0.289.0≥ 10.0, < 10.1.102.64+1 more2010-11-07
CVE-2010-3636 [CRITICAL] CWE-264 CVE-2010-3636: Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Sol Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, does not properly handle unspecified encodings during the parsing of a cross-domain policy file, which allows remote web servers to bypass intended access restrictions via unknown vectors.
nvd
CVE-2008-3872P3CRITICALCVSS 9.3≥ 8.0, ≤ 8.0.39.0≥ 9.0, ≤ 9.0.115.02008-10-06
CVE-2008-3872 [CRITICAL] CWE-264 CVE-2008-3872: Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.
nvd
CVE-2010-2216P3CRITICALCVSS 9.3≤ 10.1.53.64v7.0+45 more2010-08-11
CVE-2010-2216 [CRITICAL] CVE-2010-2216: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.
nvd
CVE-2010-0209P3CRITICALCVSS 9.3≤ 10.1.53.64v7.0+45 more2010-08-11
CVE-2010-0209 [CRITICAL] CWE-94 CVE-2010-0209: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.
nvd
CVE-2010-2214P3CRITICALCVSS 9.3≤ 10.1.53.64v7.0+45 more2010-08-11
CVE-2010-2214 [CRITICAL] CVE-2010-2214: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2216.
nvd
CVE-2010-2213P3CRITICALCVSS 9.3≤ 10.1.53.64v7.0+45 more2010-08-11
CVE-2010-2213 [CRITICAL] CVE-2010-2213: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows att Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2214, and CVE-2010-2216.
nvd
CVE-2011-0621P3CRITICALCVSS 9.3≤ 10.2.159.1v6.0.21.0+82 more2011-05-13
CVE-2011-0621 [CRITICAL] CVE-2011-0621: Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.2 Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0619, CVE-2011-0620, and CVE-2011-0622.
nvd
Adobe Flash Player vulnerabilities | cvebase