cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 53 of 55
CVE-2015-3102P4MEDIUMCVSS 5.0≤ 11.2.202.460≤ 13.0.0.289+17 more2015-06-10
CVE-2015-3102 [MEDIUM] CVE-2015-3102: Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.
nvd
CVE-2015-3099P4MEDIUMCVSS 5.0≤ 11.2.202.460≤ 13.0.0.289+17 more2015-06-10
CVE-2015-3099 [MEDIUM] CVE-2015-3099: Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.
nvd
CVE-2015-3098P4MEDIUMCVSS 5.0≤ 13.0.0.289v14.0.0.125+17 more2015-06-10
CVE-2015-3098 [MEDIUM] CWE-200 CVE-2015-3098: Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and befo
nvd
CVE-2007-6245P4MEDIUMCVSS 5.8v7.0v8.0+1 more2007-12-20
CVE-2007-6245 [MEDIUM] CWE-119 CVE-2007-6245: Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote atta Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.
nvd
CVE-2013-0637P4MEDIUMCVSS 5.0≥ 10.3, < 10.3.183.63≥ 11.6, < 11.6.602.168+5 more2013-02-12
CVE-2013-0637 [MEDIUM] CWE-200 CVE-2013-0637: Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 an Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allow atta
nvd
CVE-2015-8453P4MEDIUMCVSS 4.3≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8453 [MEDIUM] CVE-2015-8453: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to bypass the ASLR protection mechanism via JIT data, a different vulnerability than CVE-2015-8409 and CVE-20
nvd
CVE-2015-5572P4MEDIUMCVSS 5.0≤ 11.2.202.508≤ 13.0.0.289+24 more2015-09-22
CVE-2015-5572 [MEDIUM] CWE-200 CVE-2015-5572: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2. Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
nvd
CVE-2012-4171P4MEDIUMCVSS 5.0≤ 10.3.183.19v2+123 more2012-08-31
CVE-2012-4171 [MEDIUM] CVE-2012-4171: Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 1 Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allow attackers to cause a denial of service (application crash)
nvd
CVE-2012-0769P4MEDIUMCVSS 5.0≤ 10.3.183.15v2+109 more2012-03-05
CVE-2012-0769 [MEDIUM] CWE-189 CVE-2012-0769: Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and S Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2007-6246P4MEDIUMCVSS 4.4≤ 9.0.48.02007-12-20
CVE-2007-6246 [MEDIUM] CWE-264 CVE-2007-6246: Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on L Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges.
nvd
CVE-2011-2429P4MEDIUMCVSS 5.0≤ 10.3.183.7v6.0.21.0+94 more2011-09-22
CVE-2011-2429 [MEDIUM] CWE-264 CVE-2011-2429: Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186. Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, related to a "security control bypass."
nvd
CVE-2014-0532P4MEDIUMCVSS 4.3≤ 13.0.0.214v13.0.0.182+29 more2014-06-11
CVE-2014-0532 [MEDIUM] CVE-2014-0532: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14. Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a
nvd
CVE-2014-0533P4MEDIUMCVSS 4.3≤ 13.0.0.214v13.0.0.182+29 more2014-06-11
CVE-2014-0533 [MEDIUM] CVE-2014-0533: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14. Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a
nvd
CVE-2014-0531P4MEDIUMCVSS 4.3≤ 13.0.0.214v13.0.0.182+29 more2014-06-11
CVE-2014-0531 [MEDIUM] CWE-79 CVE-2014-0531: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14. Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vect
nvd
CVE-2011-0579P4MEDIUMCVSS 5.0≤ 10.2.159.1v6.0.21.0+82 more2011-05-13
CVE-2011-0579 [MEDIUM] CWE-200 CVE-2011-0579: Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.2 Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2007-2022P4MEDIUMCVSS 6.8v7.0.25v8.0+3 more2007-04-13
CVE-2007-2022 [MEDIUM] CWE-200 CVE-2007-2022: Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613 Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
nvd
CVE-2016-4178P4MEDIUMCVSS 4.3≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4178 [MEDIUM] CWE-863 CVE-2016-4178: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
nvd
CVE-2008-1655P4MEDIUMCVSS 4.3≤ 9.0.115.02008-04-09
CVE-2008-1655 [MEDIUM] CWE-79 CVE-2008-1655: Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, mak Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
nvd
CVE-2008-5361P4MEDIUMCVSS 4.3≥ 9.0.16.0, < 9.0.151.0≥ 10, < 10.0.12.362008-12-08
CVE-2008-5361 [MEDIUM] CWE-399 CVE-2008-5361: The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.1 The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from proce
nvd
CVE-2012-2038P4MEDIUMCVSS 4.3≤ 11.2.202.235≤ 11.1.115.8+1 more2012-06-09
CVE-2012-2038 [MEDIUM] CWE-200 CVE-2012-2038: Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 1 Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to bypass intended access restrictions and obtain sensitive information
nvd
Adobe Flash Player vulnerabilities | cvebase