Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
46
Severity breakdown
CRITICAL607HIGH369MEDIUM104LOW1

Vulnerabilities

Page 54 of 55
CVE-2008-4503MEDIUMCVSS 6.8≤ 9.0.124.0v7.0+18 more2008-10-09
CVE-2008-4503 [MEDIUM] CVE-2008-4503: The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause vi The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."
nvd
CVE-2008-3872CRITICALCVSS 9.3≥ 8.0, ≤ 8.0.39.0≥ 9.0, ≤ 9.0.115.02008-10-06
CVE-2008-3872 [CRITICAL] CWE-264 CVE-2008-3872: Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.
nvd
CVE-2007-0071CRITICALCVSS 9.3≥ 8.0, ≤ 8.0.39.0≥ 9.0, ≤ 9.0.115.02008-04-09
CVE-2007-0071 [CRITICAL] CWE-189 CVE-2007-0071: Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remot Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.
nvd
CVE-2007-6019CRITICALCVSS 9.3PoC≤ 9.0.115.0v7.0+31 more2008-04-09
CVE-2007-6019 [CRITICAL] CVE-2007-6019: Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execu Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
nvd
CVE-2008-1655MEDIUMCVSS 4.3≤ 9.0.115.02008-04-09
CVE-2008-1655 [MEDIUM] CWE-79 CVE-2008-1655: Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, mak Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
nvd
CVE-2007-6637MEDIUMCVSS 4.3v7.0.25v7.0.63+16 more2008-01-04
CVE-2007-6637 [MEDIUM] CVE-2007-6637: Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.
nvd
CVE-2007-6243CRITICALCVSS 9.3≤ 9.0.48.02007-12-20
CVE-2007-6243 [CRITICAL] CWE-264 CVE-2007-6243: Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficien Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.
nvd
CVE-2007-6245MEDIUMCVSS 5.8v7.0v8.0+1 more2007-12-20
CVE-2007-6245 [MEDIUM] CWE-119 CVE-2007-6245: Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote atta Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.
nvd
CVE-2007-6244MEDIUMCVSS 4.3PoCv8.0v9.02007-12-20
CVE-2007-6244 [MEDIUM] CWE-79 CVE-2007-6244: Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.
nvd
CVE-2007-6246MEDIUMCVSS 4.4≤ 9.0.48.02007-12-20
CVE-2007-6246 [MEDIUM] CWE-264 CVE-2007-6246: Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on L Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges.
nvd
CVE-2007-6242MEDIUMCVSS 6.8≥ 9.0.16.0, ≤ 9.0.48.02007-12-20
CVE-2007-6242 [MEDIUM] CWE-20 CVE-2007-6242: Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors."
nvd
CVE-2007-5476CRITICALCVSS 10.0≤ 9.0.47.02007-10-18
CVE-2007-5476 [CRITICAL] CVE-2007-5476: Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9 Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Severe" impact and unknown attack vectors.
nvd
CVE-2007-4324MEDIUMCVSS 5.0≤ 9.0.114.02007-08-14
CVE-2007-4324 [MEDIUM] CWE-264 CVE-2007-4324: ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earl ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEve
nvd
CVE-2007-3456CRITICALCVSS 9.3PoC≤ 9.0.45.0v9.0.16+7 more2007-07-11
CVE-2007-3456 [CRITICAL] CWE-189 CVE-2007-3456: Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
nvd
CVE-2007-3457MEDIUMCVSS 4.3≤ 8.0.34.02007-07-11
CVE-2007-3457 [MEDIUM] CWE-352 CVE-2007-3457: Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might a Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.
nvd
CVE-2007-2022MEDIUMCVSS 6.8v7.0.25v8.0+3 more2007-04-13
CVE-2007-2022 [MEDIUM] CWE-200 CVE-2007-2022: Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613 Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
nvd
CVE-2006-5330MEDIUMCVSS 5.0≤ 7.0.63≤ 7.0_r67+2 more2006-10-17
CVE-2006-5330 [MEDIUM] CWE-79 CVE-2006-5330: CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functio
nvd
CVE-2006-4640MEDIUMCVSS 6.8≤ 8.0.24.0v8+1 more2006-09-12
CVE-2006-4640 [MEDIUM] CWE-264 CVE-2006-4640: Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attacker Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors.
nvd
CVE-2006-3311MEDIUMCVSS 5.1≤ 8.0.24.0v8+1 more2006-09-12
CVE-2006-3311 [MEDIUM] CVE-2006-3311: Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.
nvd
CVE-2006-3587MEDIUMCVSS 5.1v8.0.24.02006-07-13
CVE-2006-3587 [MEDIUM] CVE-2006-3587: Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to exe Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.
nvd