Adobe Flash Player vulnerabilities
1,081 known vulnerabilities affecting adobe/flash_player.
Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1
Vulnerabilities
Page 50 of 55
CVE-2015-3126P3HIGHCVSS 7.5≤ 11.2.202.468≤ 13.0.0.289+20 more2015-07-09
CVE-2015-3126 [HIGH] CVE-2015-3126: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unkno
nvd
CVE-2014-0499P3HIGHCVSS 7.8≥ 11.0, < 11.7.700.269≥ 11.8, < 11.8.800.175+2 more2014-02-21
CVE-2014-0499 [HIGH] CWE-264 CVE-2014-0499: Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac
Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the
nvd
CVE-2007-5476P3CRITICALCVSS 10.0≤ 9.0.47.02007-10-18
CVE-2007-5476 [CRITICAL] CVE-2007-5476: Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9
Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Severe" impact and unknown attack vectors.
nvd
CVE-2014-0503P3MEDIUMCVSS 6.4≥ 11.0, < 11.2.202.346≥ 11.0, < 11.7.700.272+1 more2014-03-12
CVE-2014-0503 [MEDIUM] CWE-264 CVE-2014-0503: Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS
Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2018-5001P3MEDIUMCVSS 6.5≤ 29.0.0.1712018-07-09
CVE-2018-5001 [MEDIUM] CWE-125 CVE-2018-5001: Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Success
Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2009-1865P3CRITICALCVSS 9.3≤ 10.0.22.87v7.0+29 more2009-07-31
CVE-2009-1865 [CRITICAL] CVE-2009-1865: Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows a
Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, related to a "null pointer vulnerability."
nvd
CVE-2017-3085P3HIGHCVSS 7.4≤ 26.0.0.1372017-08-11
CVE-2017-3085 [HIGH] CWE-601 CVE-2017-3085: Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads t
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
nvd
CVE-2018-15983P3HIGHCVSS 7.8≤ 31.0.0.1532019-01-18
CVE-2018-15983 [HIGH] CWE-426 CVE-2018-15983: Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library lo
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2006-3587P3MEDIUMCVSS 5.1v8.0.24.02006-07-13
CVE-2006-3587 [MEDIUM] CVE-2006-3587: Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to exe
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
nvd
CVE-2015-3085P3MEDIUMCVSS 6.4≤ 13.0.0.264v14.0.0.125+16 more2015-05-13
CVE-2015-3085 [MEDIUM] CVE-2015-3085: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow remote attackers to bypass intended restrictions on filesystem write operations via unspecified vectors, a differen
nvd
CVE-2007-6243P3CRITICALCVSS 9.3≤ 9.0.48.02007-12-20
CVE-2007-6243 [CRITICAL] CWE-264 CVE-2007-6243: Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficien
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.
nvd
CVE-2006-5330P4MEDIUMCVSS 5.0≤ 7.0.63≤ 7.0_r67+2 more2006-10-17
CVE-2006-5330 [MEDIUM] CWE-79 CVE-2006-5330: CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and
CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functio
nvd
CVE-2017-3000P4MEDIUMCVSS 6.5≤ 24.0.0.2212017-03-14
CVE-2017-3000 [MEDIUM] CVE-2017-3000: Adobe Flash Player versions 24.0.0.221 and earlier have a vulnerability in the random number generat
Adobe Flash Player versions 24.0.0.221 and earlier have a vulnerability in the random number generator used for constant blinding. Successful exploitation could lead to information disclosure.
nvd
CVE-2011-2139P4MEDIUMCVSS 6.4≤ 10.3.181.36v6.0.21.0+90 more2011-08-10
CVE-2011-2139 [MEDIUM] CWE-264 CVE-2011-2139: Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
nvd
CVE-2017-2938P4MEDIUMCVSS 6.5≤ 24.0.0.1862017-01-11
CVE-2017-2938 [MEDIUM] CVE-2017-2938: Adobe Flash Player versions 24.0.0.186 and earlier have a security bypass vulnerability related to h
Adobe Flash Player versions 24.0.0.186 and earlier have a security bypass vulnerability related to handling TCP connections.
nvd
CVE-2006-4640P3MEDIUMCVSS 6.8≤ 8.0.24.0v8+1 more2006-09-12
CVE-2006-4640 [MEDIUM] CWE-264 CVE-2006-4640: Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attacker
Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors.
nvd
CVE-2016-4271P4MEDIUMCVSS 6.5≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4271 [MEDIUM] CVE-2016-4271: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4277 and CVE-2016-4278, aka a "local-with-filesystem Flash sandbox bypass" is
nvd
CVE-2018-12824P4MEDIUMCVSS 5.9≤ 30.0.0.1542018-08-29
CVE-2018-12824 [MEDIUM] CWE-125 CVE-2018-12824: Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful explo
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2012-0725P4CRITICALCVSS 9.3fixed in 11.2.202.229fixed in 11.2.202.228+2 more2012-04-06
CVE-2012-0725 [CRITICAL] CVE-2012-0725: Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to caus
Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0724.
nvd
CVE-2012-0724P4CRITICALCVSS 9.3fixed in 11.2.202.229fixed in 11.2.202.228+2 more2012-04-06
CVE-2012-0724 [CRITICAL] CWE-119 CVE-2012-0724: Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to caus
Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0725.
nvd