cbcvebase.

Adobe Flash Player Desktop Runtime vulnerabilities

294 known vulnerabilities affecting adobe/flash_player_desktop_runtime.

Total CVEs
294
CISA KEV
8
actively exploited
Public exploits
45
Exploited in wild
10
Severity breakdown
CRITICAL18HIGH260MEDIUM16

Vulnerabilities

Page 2 of 15
CVE-2016-0998P2HIGHCVSS 8.8PoC≤ 20.2.2.3062016-03-12
CVE-2016-0998 [HIGH] CVE-2016-0998: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2016-0985P2HIGHCVSS 8.8PoC≤ 20.0.0.2862016-02-10
CVE-2016-0985 [HIGH] CWE-843 CVE-2016-0985: Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and bef Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion."
nvd
CVE-2016-1001P2HIGHCVSS 8.8PoC≤ 20.2.2.3062016-03-12
CVE-2016-1001 [HIGH] CWE-787 CVE-2016-1001: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0 Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-1011P2HIGHCVSS 8.8PoC≤ 21.0.0.1972016-04-09
CVE-2016-1011 [HIGH] CWE-416 CVE-2016-1011: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
nvd
CVE-2016-0974P2HIGHCVSS 8.8PoC≤ 20.0.0.2862016-02-10
CVE-2016-0974 [HIGH] CVE-2016-0974: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability t
nvd
CVE-2016-1013P2HIGHCVSS 8.8PoC≤ 21.0.0.1972016-04-09
CVE-2016-1013 [HIGH] CVE-2016-1013: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
nvd
CVE-2016-4138P2CRITICALCVSS 9.8PoC≤ 21.0.0.2422016-06-16
CVE-2016-4138 [CRITICAL] CVE-2016-4138: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2017-2992P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2992 [HIGH] CWE-787 CVE-2017-2992: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability w Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2986P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2986 [HIGH] CWE-787 CVE-2017-2986: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability i Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4179P2HIGHCVSS 8.8PoC≤ 22.0.0.1922016-07-13
CVE-2016-4179 [HIGH] CVE-2016-4179: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4
nvd
CVE-2016-4175P2HIGHCVSS 8.8PoC≤ 22.0.0.1922016-07-13
CVE-2016-4175 [HIGH] CVE-2016-4175: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4
nvd
CVE-2018-4935P2HIGHCVSS 8.8PoC≤ 29.0.0.1132018-05-19
CVE-2018-4935 [HIGH] CWE-787 CVE-2018-4935: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerabi Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2018-4937P2HIGHCVSS 8.8PoC≤ 29.0.0.1132018-05-19
CVE-2018-4937 [HIGH] CWE-787 CVE-2018-4937: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerabi Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2016-4273P2HIGHCVSS 8.8PoC≤ 23.0.0.1622016-10-13
CVE-2016-4273 [HIGH] CWE-787 CVE-2016-4273: Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CV
nvd
CVE-2016-4275P2HIGHCVSS 8.8PoC≤ 22.0.0.2112016-09-14
CVE-2016-4275 [HIGH] CVE-2016-4275: Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CVE-2016-4
nvd
CVE-2016-4232P2HIGHCVSS 7.5PoC≤ 22.0.0.1922016-07-13
CVE-2016-4232 [HIGH] CWE-401 CVE-2016-4232: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information from process memory via unspecified vectors.
nvd
CVE-2016-1002P2HIGHCVSS 8.8PoC≤ 20.2.2.3062016-03-12
CVE-2016-1002 [HIGH] CVE-2016-1002: Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe
nvd
CVE-2016-0965P2HIGHCVSS 8.8PoC≤ 20.0.0.2862016-02-10
CVE-2016-0965 [HIGH] CVE-2016-0965: Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and bef Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different
nvd
CVE-2016-0964P2HIGHCVSS 8.8PoC≤ 20.0.0.2862016-02-10
CVE-2016-0964 [HIGH] CWE-787 CVE-2016-0964: Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and bef Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a d
nvd
CVE-2016-0967P2HIGHCVSS 8.8PoC≤ 20.0.0.2862016-02-10
CVE-2016-0967 [HIGH] CVE-2016-0967: Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and bef Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different
nvd
Adobe Flash Player Desktop Runtime vulnerabilities | cvebase