cbcvebase.

Adobe Flash Player Desktop Runtime vulnerabilities

294 known vulnerabilities affecting adobe/flash_player_desktop_runtime.

Total CVEs
294
CISA KEV
8
actively exploited
Public exploits
45
Exploited in wild
10
Severity breakdown
CRITICAL18HIGH260MEDIUM16

Vulnerabilities

Page 3 of 15
CVE-2017-2985P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2985 [HIGH] CWE-416 CVE-2017-2985: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3068P2HIGHCVSS 8.8PoC≤ 25.0.0.163≤ 25.0.0.1482017-05-09
CVE-2017-3068 [HIGH] CWE-787 CVE-2017-3068: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2988P2HIGHCVSS 8.8PoC≤ 24.0.0.1942017-02-15
CVE-2017-2988 [HIGH] CWE-787 CVE-2017-2988: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing garbage collection. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3106P2HIGHCVSS 8.8PoC≤ 26.0.0.1372017-08-11
CVE-2017-3106 [HIGH] CWE-704 CVE-2017-3106: Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4176P2HIGHCVSS 8.8PoC≤ 22.0.0.1922016-07-13
CVE-2016-4176 [HIGH] CWE-787 CVE-2016-4176: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4177.
nvd
CVE-2016-4177P2HIGHCVSS 8.8PoC≤ 22.0.0.1922016-07-13
CVE-2016-4177 [HIGH] CVE-2016-4177: Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4176.
nvd
CVE-2016-4135P2HIGHCVSS 8.8PoC≤ 21.0.0.2422016-06-16
CVE-2016-4135 [HIGH] CVE-2016-4135: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4137P2HIGHCVSS 8.8PoC≤ 21.0.0.2422016-06-16
CVE-2016-4137 [HIGH] CVE-2016-4137: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2016-4136P2HIGHCVSS 8.8PoC≤ 21.0.0.2422016-06-16
CVE-2016-4136 [HIGH] CVE-2016-4136: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash l Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
nvd
CVE-2018-4936P3MEDIUMCVSS 6.5PoC≤ 29.0.0.1132018-05-19
CVE-2018-4936 [MEDIUM] CWE-119 CVE-2018-4936: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2015-8652P3HIGHCVSS 8.8PoC≤ 19.0.0.2452016-03-04
CVE-2015-8652 [HIGH] CVE-2015-8652: Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and bef Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via crafted M
nvd
CVE-2018-4934P3MEDIUMCVSS 6.5PoC≤ 29.0.0.1132018-05-19
CVE-2018-4934 [MEDIUM] CWE-125 CVE-2018-4934: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerabil Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2016-4121P3CRITICALCVSS 9.8≤ 21.0.0.2262016-06-16
CVE-2016-4121 [CRITICAL] CVE-2016-4121: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1097, CVE-2016-1106, CVE-2016-1107, CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016
nvd
CVE-2018-5007P3HIGHCVSS 8.8≤ 30.0.0.1132018-07-20
CVE-2018-5007 [HIGH] CWE-704 CVE-2018-5007: Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful e Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2017-2984P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2984 [HIGH] CWE-787 CVE-2017-2984: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability i Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the h264 decoder routine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4222P3HIGHCVSS 8.8≤ 22.0.0.1922016-07-13
CVE-2016-4222 [HIGH] CVE-2016-4222: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-423
nvd
CVE-2016-0994P3HIGHCVSS 8.8≤ 20.2.2.3062016-03-12
CVE-2016-0994 [HIGH] CVE-2016-0994: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafte
nvd
CVE-2016-6931P3HIGHCVSS 8.8≤ 22.0.0.2112016-09-14
CVE-2016-6931 [HIGH] CVE-2016-6931: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4272, CVE-2016-4279, CVE-2016-6921, CVE-2016-6923, CVE-2016-6925, CVE-2016-6926, CVE-2016-692
nvd
CVE-2016-0996P3HIGHCVSS 8.8≤ 20.2.2.3062016-03-12
CVE-2016-0996 [HIGH] CVE-2016-0996: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 1 Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments,
nvd
CVE-2016-4248P3HIGHCVSS 8.8≤ 22.0.0.1922016-07-13
CVE-2016-4248 [HIGH] CVE-2016-4248: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4222, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-422
nvd
Adobe Flash Player Desktop Runtime vulnerabilities | cvebase