cbcvebase.

Adobe Flash Player vulnerabilities

1,081 known vulnerabilities affecting adobe/flash_player.

Total CVEs
1,081
CISA KEV
36
actively exploited
Public exploits
183
Exploited in wild
67
Severity breakdown
CRITICAL606HIGH370MEDIUM104LOW1

Vulnerabilities

Page 8 of 55
CVE-2015-8428P2CRITICALCVSS 10.0PoC≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8428 [CRITICAL] CVE-2015-8428: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2015-8426P2CRITICALCVSS 10.0PoC≤ 11.2.202.548≤ 18.0.0.261+4 more2015-12-10
CVE-2015-8426 [CRITICAL] CVE-2015-8426: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2016-4138P2CRITICALCVSS 9.8PoC≤ 21.0.0.242≤ 11.2.202.621+1 more2016-06-16
CVE-2016-4138 [CRITICAL] CVE-2016-4138: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2017-3076P2CRITICALCVSS 9.8PoC≤ 25.0.0.1712017-06-20
CVE-2017-3076 [CRITICAL] CWE-119 CVE-2017-3076: Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2992P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2992 [HIGH] CWE-787 CVE-2017-2992: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability w Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-8044P2CRITICALCVSS 10.0PoC≤ 11.2.202.540≤ 18.0.0.255+3 more2015-11-11
CVE-2015-8044 [CRITICAL] CVE-2015-8044: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on W Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than C
nvd
CVE-2015-3118P2CRITICALCVSS 10.0PoC≤ 13.0.0.289v14.0.0.125+20 more2015-07-09
CVE-2015-3118 [CRITICAL] CVE-2015-3118: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnera
nvd
CVE-2017-2986P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2986 [HIGH] CWE-787 CVE-2017-2986: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability i Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-5118P2CRITICALCVSS 10.0PoC≤ 13.0.0.289v14.0.0.125+20 more2015-07-09
CVE-2015-5118 [CRITICAL] CVE-2015-5118: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabi
nvd
CVE-2015-3128P2CRITICALCVSS 10.0PoC≤ 13.0.0.289v14.0.0.125+20 more2015-07-09
CVE-2015-3128 [CRITICAL] CVE-2015-3128: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnera
nvd
CVE-2017-2933P2HIGHCVSS 8.8PoC≤ 24.0.0.1862017-01-11
CVE-2017-2933 [HIGH] CWE-787 CVE-2017-2933: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability r Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2934P2HIGHCVSS 8.8PoC≤ 24.0.0.1862017-01-11
CVE-2017-2934 [HIGH] CWE-787 CVE-2017-2934: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability w Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4179P2HIGHCVSS 8.8PoC≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4179 [HIGH] CVE-2016-4179: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4
nvd
CVE-2016-4175P2HIGHCVSS 8.8PoC≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4175 [HIGH] CVE-2016-4175: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4
nvd
CVE-2018-4935P2HIGHCVSS 8.8PoC≤ 29.0.0.1132018-05-19
CVE-2018-4935 [HIGH] CWE-787 CVE-2018-4935: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerabi Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2018-4937P2HIGHCVSS 8.8PoC≤ 29.0.0.1132018-05-19
CVE-2018-4937 [HIGH] CWE-787 CVE-2018-4937: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerabi Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2016-4273P2HIGHCVSS 8.8PoC≤ 23.0.0.162≤ 18.0.0.375+1 more2016-10-13
CVE-2016-4273 [HIGH] CWE-787 CVE-2016-4273: Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CV
nvd
CVE-2016-4275P2HIGHCVSS 8.8PoC≤ 11.2.202.632≤ 22.0.0.211+1 more2016-09-14
CVE-2016-4275 [HIGH] CVE-2016-4275: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CVE-2016-4
nvd
CVE-2015-3134P2CRITICALCVSS 10.0PoC≤ 11.2.202.468≤ 13.0.0.289+20 more2015-07-09
CVE-2015-3134 [CRITICAL] CVE-2015-3134: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a d
nvd
CVE-2016-4232P2HIGHCVSS 7.5PoC≤ 18.0.0.360≤ 22.0.0.192+1 more2016-07-13
CVE-2016-4232 [HIGH] CWE-401 CVE-2016-4232: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information from process memory via unspecified vectors.
nvd
Adobe Flash Player vulnerabilities | cvebase