cbcvebase.

Adobe Flash Player Desktop Runtime vulnerabilities

294 known vulnerabilities affecting adobe/flash_player_desktop_runtime.

Total CVEs
294
CISA KEV
8
actively exploited
Public exploits
45
Exploited in wild
10
Severity breakdown
CRITICAL18HIGH260MEDIUM16

Vulnerabilities

Page 11 of 15
CVE-2015-8821P3HIGHCVSS 8.8≤ 19.0.0.2452016-03-04
CVE-2015-8821 [HIGH] CVE-2015-8821: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafted MPEG-4 data, a different vulnerability t
nvd
CVE-2015-8658P3HIGHCVSS 8.8≤ 19.0.0.2452016-03-04
CVE-2015-8658 [HIGH] CVE-2015-8658: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and memory corruption
nvd
CVE-2015-8823P3HIGHCVSS 8.8≤ 19.0.0.2452016-04-22
CVE-2015-8823 [HIGH] CVE-2015-8823: Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18. Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafted t
nvd
CVE-2017-3071P3HIGHCVSS 8.8≤ 25.0.0.163≤ 25.0.0.1482017-05-09
CVE-2017-3071 [HIGH] CWE-416 CVE-2017-3071: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2993P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2993 [HIGH] CWE-416 CVE-2017-2993: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability related to event handlers. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2982P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2982 [HIGH] CWE-416 CVE-2017-2982: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in a routine related to player shutdown. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7880P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7880 [HIGH] CWE-416 CVE-2016-7880: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability when setting the length property of an array object. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7881P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7881 [HIGH] CWE-416 CVE-2016-7881: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class when handling conversion to an object. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3001P3HIGHCVSS 8.8≤ 24.0.0.2212017-03-14
CVE-2017-3001 [HIGH] CWE-416 CVE-2017-3001: Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to garbage collection in the ActionScript 2 VM. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3070P3HIGHCVSS 8.8≤ 25.0.0.163≤ 25.0.0.1482017-05-09
CVE-2017-3070 [HIGH] CWE-787 CVE-2017-3070: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the ConvolutionFilter class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3069P3HIGHCVSS 8.8≤ 25.0.0.163≤ 25.0.0.1482017-05-09
CVE-2017-3069 [HIGH] CWE-787 CVE-2017-3069: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BlendMode class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3072P3HIGHCVSS 8.8≤ 25.0.0.163≤ 25.0.0.1482017-05-09
CVE-2017-3072 [HIGH] CWE-787 CVE-2017-3072: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7876P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7876 [HIGH] CWE-787 CVE-2016-7876: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable mem Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Clipboard class related to data handling functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2996P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2996 [HIGH] CWE-787 CVE-2017-2996: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in Primetime SDK. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3073P3HIGHCVSS 8.8≤ 25.0.0.163≤ 25.0.0.1482017-05-09
CVE-2017-3073 [HIGH] CWE-416 CVE-2017-3073: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display objects, aka memory corruption. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7890P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7890 [HIGH] CVE-2016-7890: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have security bypass vu Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have security bypass vulnerability in the implementation of the same origin policy.
nvd
CVE-2016-4150P3HIGHCVSS 8.8≤ 21.0.0.2422016-06-16
CVE-2016-4150 [HIGH] CWE-787 CVE-2016-4150: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4156P3HIGHCVSS 8.8≤ 21.0.0.2422016-06-16
CVE-2016-4156 [HIGH] CVE-2016-4156: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4154P3HIGHCVSS 8.8≤ 21.0.0.2422016-06-16
CVE-2016-4154 [HIGH] CWE-787 CVE-2016-4154: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4152P3HIGHCVSS 8.8≤ 21.0.0.2422016-06-16
CVE-2016-4152 [HIGH] CWE-787 CVE-2016-4152: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd