Adobe Flash Player Desktop Runtime vulnerabilities
294 known vulnerabilities affecting adobe/flash_player_desktop_runtime.
Total CVEs
294
CISA KEV
8
actively exploited
Public exploits
45
Exploited in wild
10
Severity breakdown
CRITICAL18HIGH260MEDIUM16
Vulnerabilities
Page 5 of 15
CVE-2018-15981P3CRITICALCVSS 9.8≤ 31.0.0.1482018-11-29
CVE-2018-15981 [CRITICAL] CWE-704 CVE-2018-15981: Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploit
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7020P3HIGHCVSS 8.8≤ 22.0.0.1922016-10-05
CVE-2016-7020 [HIGH] CVE-2016-7020: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4222, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-422
nvd
CVE-2016-1031P3HIGHCVSS 8.8≤ 21.0.0.1972016-04-09
CVE-2016-1031 [HIGH] CVE-2016-1031: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1017.
nvd
CVE-2016-0991P3HIGHCVSS 8.8≤ 20.2.2.3062016-03-12
CVE-2016-0991 [HIGH] CVE-2016-0991: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2016-0988P3HIGHCVSS 8.8≤ 20.2.2.3062016-03-12
CVE-2016-0988 [HIGH] CVE-2016-0988: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerabili
nvd
CVE-2016-7868P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7868 [HIGH] CWE-787 CVE-2016-7868: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buf
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to alternation functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7867P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7867 [HIGH] CWE-787 CVE-2016-7867: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buf
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to bookmarking in searches. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4287P3HIGHCVSS 8.8≤ 22.0.0.2112016-09-14
CVE-2016-4287 [HIGH] CWE-190 CVE-2016-4287: Integer overflow in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on
Integer overflow in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-1015P3HIGHCVSS 8.8≤ 21.0.0.1972016-04-09
CVE-2016-1015 [HIGH] CWE-843 CVE-2016-1015: Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code by overriding NetConnection object properties to leverage an unspecified "type confusion," a different vulnerability than CVE-2016-1019.
nvd
CVE-2019-8069P3CRITICALCVSS 9.8≤ 32.0.0.2382019-09-12
CVE-2019-8069 [CRITICAL] CWE-346 CVE-2019-8069: Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Orig
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
nvd
CVE-2016-1016P3HIGHCVSS 8.8≤ 21.0.0.1972016-04-09
CVE-2016-1016 [HIGH] CVE-2016-1016: Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18.
Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via a flash.geom.Matrix callback, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1017, and CVE-2
nvd
CVE-2016-0993P3HIGHCVSS 8.8≤ 20.2.2.3062016-03-12
CVE-2016-0993 [HIGH] CVE-2016-0993: Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2
nvd
CVE-2016-0963P3HIGHCVSS 8.8≤ 20.2.2.3062016-03-12
CVE-2016-0963 [HIGH] CWE-190 CVE-2016-0963: Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability th
nvd
CVE-2016-7869P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7869 [HIGH] CWE-787 CVE-2016-7869: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buf
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to backtrack search functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7870P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7870 [HIGH] CWE-787 CVE-2016-7870: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buf
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-8070P3CRITICALCVSS 9.8≤ 32.0.0.2382019-09-12
CVE-2019-8070 [CRITICAL] CWE-416 CVE-2019-8070: Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
nvd
CVE-2015-0312P3CRITICALCVSS 9.3≤ 16.0.0.2872015-01-28
CVE-2015-0312 [CRITICAL] CWE-415 CVE-2015-0312: Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-7875P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7875 [HIGH] CWE-190 CVE-2016-7875: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable int
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable integer overflow vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7872P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7872 [HIGH] CWE-416 CVE-2016-7872: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class related to objects at multiple presentation levels. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4249P3HIGHCVSS 8.8≤ 22.0.0.1922016-07-13
CVE-2016-4249 [HIGH] CWE-787 CVE-2016-4249: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors.
nvd