Showing 25 vulnerabilities on this page for Flash Player

Signals CISA KEV Ransomware Nuclei
Adobe vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Exploitable NULL pointer deref could lead to arbitrary code execution

Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.

CWE-476Oct 14, 2020
CVSS7.0v3.1EPSS4.26%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

CWE-346Sep 27, 2019
CVSS7.5v3.1EPSS2.62%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

CWE-416Sep 12, 2019
CVSS9.8v3.1EPSS6.27%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

CWE-346Sep 12, 2019
CVSS9.8v3.1EPSS4.53%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Use-After-Free Vulnerability

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CWE-416Jan 18, 2019
CVSS7.8v3.1EPSS82.5%PoCs5SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CWE-704Nov 29, 2018
CVSS9.8v3.0EPSS11.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.

CWE-200Sep 25, 2018
CVSS7.5v3.0EPSS7.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Stack-based Buffer Overflow Vulnerability

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CWE-121CWE-787Jul 9, 2018
CVSS7.8v3.1EPSS25.4%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Use-After-Free Vulnerability

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

CWE-416Feb 6, 2018
CVSS7.8v3.1EPSS89.5%PoCs13SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Type Confusion Vulnerability

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

CWE-843Oct 21, 2017
CVSS8.8v3.1EPSS12%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

CWE-416Dec 15, 2016
CVSS8.8v3.1EPSS18.8%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

CWE-416Nov 1, 2016
CVSS8.8v3.1EPSS25.2%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

Jun 16, 2016
CVSS9.8v3.1EPSS20.2%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

May 11, 2016
CVSS9.8v3.1EPSS94.4%PoCs3SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

Apr 7, 2016
CVSS9.8v3.1EPSS22.5%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Integer Overflow Vulnerability

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

CWE-189CWE-190Dec 28, 2015
CVSS8.8v3.1EPSS67.9%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438.

CWE-119Dec 10, 2015
CVSS9.3v2.0EPSS7.99%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

Oct 15, 2015
CVSS7.8v3.1EPSS68.4%PoCs1SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution

Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors.

CWE-189Aug 14, 2015
CVSS10.0v2.0EPSS66%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CWE-416Jul 14, 2015
CVSS9.8v3.1EPSS18.5%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as

CWE-416Jul 14, 2015
CVSS9.8v3.1EPSS93.7%PoCs3SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.

CWE-119Jul 9, 2015
CVSS10.0v2.0EPSS5.31%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CWE-119CWE-416Jul 8, 2015
CVSS9.8v3.1EPSS99.3%PoCs6SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

CVSS9.8v3.1EPSS>99.9%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CWE-119Jun 10, 2015
CVSS10.0v2.0EPSS82.7%PoCs3SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX