cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 51 of 55
CVE-2006-3311P4MEDIUMCVSS 5.1≤ 8.0.24.0v8+1 more2006-09-12
CVE-2006-3311 [MEDIUM] CVE-2006-3311: Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.
nvd
CVE-2008-4503P3MEDIUMCVSS 6.8≤ 9.0.124.0v7.0+18 more2008-10-09
CVE-2008-4503 [MEDIUM] CVE-2008-4503: The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause vi The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."
nvd
CVE-2016-4277P4MEDIUMCVSS 6.5≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4277 [MEDIUM] CVE-2016-4277: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278.
nvd
CVE-2016-4278P4MEDIUMCVSS 6.5≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4278 [MEDIUM] CVE-2016-4278: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4277.
nvd
CVE-2016-1014P4HIGHCVSS 7.3≤ 11.2.202.577≤ 18.0.0.333+1 more2016-04-09
CVE-2016-1014 [HIGH] CWE-426 CVE-2016-1014: Untrusted search path vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x be Untrusted search path vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows local users to gain privileges via a Trojan horse resource in an unspecified directory.
nvd
CVE-2015-3096P4MEDIUMCVSS 6.8≤ 13.0.0.289v14.0.0.125+17 more2015-06-10
CVE-2015-3096 [MEDIUM] CVE-2015-3096: Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.
nvd
CVE-2017-3100P4MEDIUMCVSS 6.5≤ 26.0.0.120≤ 26.0.0.1312017-07-17
CVE-2017-3100 [MEDIUM] CWE-787 CVE-2017-3100: Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class. Successful exploitation could lead to memory address disclosure.
nvd
CVE-2008-4819P4MEDIUMCVSS 6.8≤ 9.0.124.0v7.0.69.0+16 more2008-11-10
CVE-2008-4819 [MEDIUM] CVE-2008-4819: Unspecified vulnerability in Adobe Flash Player 9.0.124.0 and earlier makes it easier for remote att Unspecified vulnerability in Adobe Flash Player 9.0.124.0 and earlier makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
nvd
CVE-2015-3044P4MEDIUMCVSS 5.0≤ 13.0.0.264v14.0.0.125+15 more2015-04-14
CVE-2015-3044 [MEDIUM] CWE-200 CVE-2015-3044: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
nvd
CVE-2019-7090P4MEDIUMCVSS 6.5≤ 32.0.0.1142019-05-24
CVE-2019-7090 [MEDIUM] CWE-125 CVE-2019-7090: Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome version Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-4933P4MEDIUMCVSS 6.5≤ 29.0.0.1132018-05-19
CVE-2018-4933 [MEDIUM] CWE-125 CVE-2018-4933: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerabil Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2017-11305P4MEDIUMCVSS 6.5≤ 27.0.0.1872017-12-13
CVE-2017-11305 [MEDIUM] CVE-2017-11305: A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unint A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data.
nvd
CVE-2015-3097P4MEDIUMCVSS 5.0≤ 13.0.0.289v14.0.0.125+16 more2015-06-10
CVE-2015-3097 [MEDIUM] CWE-200 CVE-2015-3097: Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0. Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by p
nvd
CVE-2015-0302P4MEDIUMCVSS 5.0v11.2.202.425≤ 13.0.0.259+14 more2015-01-13
CVE-2015-0302 [MEDIUM] CVE-2015-0302: Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow attackers to obtain sensitive keystroke information via unspec
nvd
CVE-2015-0337P4MEDIUMCVSS 5.0≤ 11.2.202.442≤ 13.0.0.264+15 more2015-03-13
CVE-2015-0337 [MEDIUM] CWE-264 CVE-2015-0337: Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2015-0340P4MEDIUMCVSS 5.0≤ 11.2.202.442≤ 13.0.0.264+15 more2015-03-13
CVE-2015-0340 [MEDIUM] CVE-2015-0340: Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass intended file-upload restrictions via unspecified vectors.
nvd
CVE-2010-0186P4MEDIUMCVSS 6.8≤ 10.0.42.34v6.0.21.0+45 more2010-02-15
CVE-2010-0186 [MEDIUM] CVE-2010-0186: Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
nvd
CVE-2017-3080P4MEDIUMCVSS 6.5≤ 26.0.0.120≤ 26.0.0.1312017-07-17
CVE-2017-3080 [MEDIUM] CVE-2017-3080: Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to t Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by Internet Explorer. Successful exploitation could lead to information disclosure.
nvd
CVE-2009-0114P4MEDIUMCVSS 5.8≤ 10.0.12.36v7.0+30 more2009-02-26
CVE-2009-0114 [MEDIUM] CVE-2009-0114: Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10. Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."
nvd
CVE-2015-6679P4MEDIUMCVSS 5.0≤ 11.2.202.508≤ 13.0.0.289+24 more2015-09-22
CVE-2015-6679 [MEDIUM] CWE-200 CVE-2015-6679: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
nvd
Adobe Flash Player vulnerabilities | cvebase