cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 49 of 55
CVE-2011-0620P3CRITICALCVSS 9.3≤ 10.2.159.1v6.0.21.0+82 more2011-05-13
CVE-2011-0620 [CRITICAL] CVE-2011-0620: Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.2 Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0619, CVE-2011-0621, and CVE-2011-0622.
nvd
CVE-2011-0619P3CRITICALCVSS 9.3≤ 10.2.159.1v6.0.21.0+82 more2011-05-13
CVE-2011-0619 [CRITICAL] CWE-119 CVE-2011-0619: Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.2 Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0620, CVE-2011-0621, and CVE-2011-0622.
nvd
CVE-2011-0622P3CRITICALCVSS 9.3≤ 10.2.159.1v6.0.21.0+82 more2011-05-13
CVE-2011-0622 [CRITICAL] CVE-2011-0622: Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.2 Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0619, CVE-2011-0620, and CVE-2011-0621.
nvd
CVE-2015-0325P3CRITICALCVSS 10.0≤ 11.2.202.440≤ 13.0.0.264+14 more2015-02-06
CVE-2015-0325 [CRITICAL] CVE-2015-0325: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-0326 and CVE-2015-0328.
nvd
CVE-2015-0326P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+14 more2015-02-06
CVE-2015-0326 [CRITICAL] CVE-2015-0326: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-0325 and CVE-2015-0328.
nvd
CVE-2009-1864P3CRITICALCVSS 9.3≤ 10.0.22.87v7.0+29 more2009-07-31
CVE-2009-1864 [CRITICAL] CWE-119 CVE-2009-1864: Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Ad Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2015-0328P3CRITICALCVSS 10.0≤ 13.0.0.264v14.0.0.125+14 more2015-02-06
CVE-2015-0328 [CRITICAL] CVE-2015-0328: Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-0325 and CVE-2015-0326.
nvd
CVE-2014-8442P3HIGHCVSS 7.5≥ 13.0, < 13.0.0.252≥ 14.0, ≤ 14.0.0.179+2 more2014-11-11
CVE-2014-8442 [HIGH] CWE-264 CVE-2014-8442: Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and bef Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to complete a transition from Low Integrity to Medium Integrity by leveraging incorrect permissions.
nvd
CVE-2010-2186P3CRITICALCVSS 9.3v9.0.16v9.0.20+53 more2010-06-15
CVE-2010-2186 [CRITICAL] CWE-94 CVE-2010-2186: Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Ado Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-1863P3CRITICALCVSS 9.3≤ 10.0.22.87v7.0+29 more2009-07-31
CVE-2009-1863 [CRITICAL] CWE-264 CVE-2009-1863: Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Ado Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to a "privilege escalation vulnerability."
nvd
CVE-2014-0517P3HIGHCVSS 7.5≥ 13.0, < 13.0.0.214≥ 11.0, < 11.2.202.3592014-05-14
CVE-2014-0517 [HIGH] CWE-264 CVE-2014-0517: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0518, CVE-2014-0519, and CVE-2014-0520.
nvd
CVE-2014-0519P3HIGHCVSS 7.5≥ 13.0, < 13.0.0.214≥ 11.0, < 11.2.202.3592014-05-14
CVE-2014-0519 [HIGH] CVE-2014-0519: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0518, and CVE-2014-0520.
nvd
CVE-2014-0518P3HIGHCVSS 7.5≥ 13.0, < 13.0.0.214≥ 11.0, < 11.2.202.3592014-05-14
CVE-2014-0518 [HIGH] CVE-2014-0518: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0519, and CVE-2014-0520.
nvd
CVE-2014-0520P3HIGHCVSS 7.5≥ 13.0, < 13.0.0.214≥ 11.0, < 11.2.202.3592014-05-14
CVE-2014-0520 [HIGH] CVE-2014-0520: Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0518, and CVE-2014-0519.
nvd
CVE-2014-0539P3HIGHCVSS 7.5≤ 11.2.202.378v11.2.202.223+32 more2014-07-09
CVE-2014-0539 [HIGH] CVE-2014-0539: Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0537.
nvd
CVE-2014-0537P3HIGHCVSS 7.5≤ 13.0.0.223v13.0.0.182+32 more2014-07-09
CVE-2014-0537 [HIGH] CWE-264 CVE-2014-0537: Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2. Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-20
nvd
CVE-2008-4822P3MEDIUMCVSS 6.8≤ 9.0.124.0v7.0.69.0+16 more2008-11-10
CVE-2008-4822 [MEDIUM] CWE-264 CVE-2008-4822: Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remo Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.
nvd
CVE-2019-7108P3HIGHCVSS 7.5≤ 32.0.0.1562019-05-23
CVE-2019-7108 [HIGH] CWE-125 CVE-2019-7108: Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earli Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
nvd
CVE-2019-8075P3HIGHCVSS 7.5≤ 32.0.0.207v32.0.0.192 and earlier versions2019-09-27
CVE-2019-8075 [HIGH] CVE-2019-8075: Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerab Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
nvd
CVE-2018-5000P3MEDIUMCVSS 6.5≤ 29.0.0.1712018-07-09
CVE-2018-5000 [MEDIUM] CWE-190 CVE-2018-5000: Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successfu Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
nvd
Adobe Flash Player vulnerabilities | cvebase