cbcvebase.

Adobe Flash Player Desktop Runtime vulnerabilities

294 known vulnerabilities affecting adobe/flash_player_desktop_runtime.

Total CVEs
294
CISA KEV
8
actively exploited
Public exploits
45
Exploited in wild
10
Severity breakdown
CRITICAL18HIGH260MEDIUM16

Vulnerabilities

Page 6 of 15
CVE-2016-0975P3HIGHCVSS 8.8≤ 20.0.0.2862016-02-10
CVE-2016-0975 [HIGH] CVE-2016-0975: Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18.0.0.329 and Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code by leveraging improper ref
nvd
CVE-2020-9633P3CRITICALCVSS 9.8≤ 32.0.0.3712020-06-12
CVE-2020-9633 [CRITICAL] CWE-416 CVE-2020-9633: Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0 Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-7837P3HIGHCVSS 8.8≤ 32.0.0.1712019-05-22
CVE-2019-7837 [HIGH] CWE-416 CVE-2019-7837: Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earli Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2990P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2990 [HIGH] CWE-787 CVE-2017-2990: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in the h264 decompression routine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-7096P3CRITICALCVSS 9.8≤ 32.0.0.1562019-05-23
CVE-2019-7096 [CRITICAL] CWE-416 CVE-2019-7096: Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earli Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4163P3CRITICALCVSS 9.8≤ 21.0.0.2262016-06-16
CVE-2016-4163 [CRITICAL] CVE-2016-4163: Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-20
nvd
CVE-2016-4161P3CRITICALCVSS 9.8≤ 21.0.0.2262016-06-16
CVE-2016-4161 [CRITICAL] CVE-2016-4161: Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-20
nvd
CVE-2016-4120P3CRITICALCVSS 9.8≤ 21.0.0.2262016-06-16
CVE-2016-4120 [CRITICAL] CVE-2016-4120: Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-20
nvd
CVE-2016-4160P3CRITICALCVSS 9.8≤ 21.0.0.2262016-06-16
CVE-2016-4160 [CRITICAL] CVE-2016-4160: Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-20
nvd
CVE-2016-4162P3CRITICALCVSS 9.8≤ 21.0.0.2262016-06-16
CVE-2016-4162 [CRITICAL] CVE-2016-4162: Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-20
nvd
CVE-2017-2987P3HIGHCVSS 8.8≤ 24.0.0.1942017-02-15
CVE-2017-2987 [HIGH] CWE-190 CVE-2017-2987: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerabilit Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7878P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7878 [HIGH] CWE-416 CVE-2016-7878: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the PSDK's MediaPlayer class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-4920P3HIGHCVSS 8.8≤ 28.0.0.1612018-05-19
CVE-2018-4920 [HIGH] CWE-843 CVE-2018-4920: Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2016-7879P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7879 [HIGH] CWE-416 CVE-2016-7879: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the NetConnection class when handling an attached script object. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-4945P3HIGHCVSS 8.8≤ 29.0.0.1712018-07-09
CVE-2018-4945 [HIGH] CWE-704 CVE-2018-4945: Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful e Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2016-7871P3HIGHCVSS 8.8≤ 23.0.0.2072016-12-15
CVE-2016-7871 [HIGH] CWE-787 CVE-2016-7871: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable mem Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Worker class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-6992P3HIGHCVSS 8.8≤ 23.0.0.1622016-10-13
CVE-2016-6992 [HIGH] CWE-843 CVE-2016-6992: Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion."
nvd
CVE-2016-0982P3HIGHCVSS 8.8≤ 20.0.0.2862016-02-10
CVE-2016-0982 [HIGH] CVE-2016-0982: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability t
nvd
CVE-2016-0983P3HIGHCVSS 8.8≤ 20.0.0.2862016-02-10
CVE-2016-0983 [HIGH] CVE-2016-0983: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability t
nvd
CVE-2016-0973P3HIGHCVSS 8.8≤ 20.0.0.2862016-02-10
CVE-2016-0973 [HIGH] CWE-416 CVE-2016-0973: Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18 Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via
nvd
Adobe Flash Player Desktop Runtime vulnerabilities | cvebase