Adobe Vulnerabilities and Affected Products
Vulnerabilities associated with Flash Player.
Products
Clear product- Adobe Experience Manager1,018 vulnerabilities
- Adobe Acrobat and Reader516 vulnerabilities
- Acrobat Reader447 vulnerabilities
- Adobe Commerce190 vulnerabilities
- ColdFusion149 vulnerabilities
- Illustrator149 vulnerabilities
- InDesign Desktop131 vulnerabilities
- After Effects119 vulnerabilities
- Dimension116 vulnerabilities
- Bridge114 vulnerabilities
- Animate101 vulnerabilities
- Experience Manager98 vulnerabilities
- InDesign96 vulnerabilities
- Substance3D - Stager87 vulnerabilities
- Magento Commerce85 vulnerabilities
- Adobe Framemaker82 vulnerabilities
- experience_manager78 vulnerabilities
- Substance3D - Painter78 vulnerabilities
- Flash Player70 vulnerabilities
- InCopy65 vulnerabilities
- Photoshop58 vulnerabilities
- experience_manager_cloud_service53 vulnerabilities
- acrobat_reader49 vulnerabilities
- FrameMaker48 vulnerabilities
- acrobat_reader_dc47 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-9746HIGH | Exploitable NULL pointer deref could lead to arbitrary code executionAdobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL. CWE-476Oct 14, 2020 | CVSS7.0v3.1 | EPSS4.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-8075HIGH | Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. CWE-346Sep 27, 2019 | CVSS7.5v3.1 | EPSS2.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-8070CRITICAL | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. CWE-416Sep 12, 2019 | CVSS9.8v3.1 | EPSS6.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-8069CRITICAL | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. CWE-346Sep 12, 2019 | CVSS9.8v3.1 | EPSS4.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15982HIGH | Adobe Flash Player Use-After-Free VulnerabilityFlash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. CWE-416Jan 18, 2019 | CVSS7.8v3.1 | EPSS82.5% | PoCs5 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2018-15981CRITICAL | Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. CWE-704Nov 29, 2018 | CVSS9.8v3.0 | EPSS11.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15967HIGH | Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure. CWE-200Sep 25, 2018 | CVSS7.5v3.0 | EPSS7.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5002HIGH | Adobe Flash Player Stack-based Buffer Overflow VulnerabilityAdobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | CVSS7.8v3.1 | EPSS25.4% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-4878HIGH | Adobe Flash Player Use-After-Free VulnerabilityA use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018. CWE-416Feb 6, 2018 | CVSS7.8v3.1 | EPSS89.5% | PoCs13 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2017-11292HIGH | Adobe Flash Player Type Confusion VulnerabilityAdobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution. CWE-843Oct 21, 2017 | CVSS8.8v3.1 | EPSS12% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-7892HIGH | Adobe Flash Player Use-After-Free VulnerabilityAdobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution. CWE-416Dec 15, 2016 | CVSS8.8v3.1 | EPSS18.8% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-7855HIGH | Adobe Flash Player Use-After-Free VulnerabilityUse-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016. CWE-416Nov 1, 2016 | CVSS8.8v3.1 | EPSS25.2% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4171CRITICAL | Adobe Flash Player Remote Code Execution VulnerabilityUnspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016. Jun 16, 2016 | CVSS9.8v3.1 | EPSS20.2% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4117CRITICAL | Adobe Flash Player Arbitrary Code Execution VulnerabilityAdobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016. May 11, 2016 | CVSS9.8v3.1 | EPSS94.4% | PoCs3 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2016-1019CRITICAL | Adobe Flash Player Arbitrary Code Execution VulnerabilityAdobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016. Apr 7, 2016 | CVSS9.8v3.1 | EPSS22.5% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2015-8651HIGH | Adobe Flash Player Integer Overflow VulnerabilityInteger overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors. | CVSS8.8v3.1 | EPSS67.9% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory BufferHeap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438. CWE-119Dec 10, 2015 | CVSS9.3v2.0 | EPSS7.99% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX | |
CVE-2015-7645HIGH | Adobe Flash Player Arbitrary Code Execution VulnerabilityAdobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015. Oct 15, 2015 | CVSS7.8v3.1 | EPSS68.4% | PoCs1 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code ExecutionInteger overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors. CWE-189Aug 14, 2015 | CVSS10.0v2.0 | EPSS66% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2015-5123CRITICAL | Adobe Flash Player Use-After-Free VulnerabilityUse-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015. CWE-416Jul 14, 2015 | CVSS9.8v3.1 | EPSS18.5% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2015-5122CRITICAL | Adobe Flash Player Use-After-Free VulnerabilityUse-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as … CWE-416Jul 14, 2015 | CVSS9.8v3.1 | EPSS93.7% | PoCs3 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory BufferAdobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431. CWE-119Jul 9, 2015 | CVSS10.0v2.0 | EPSS5.31% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX | |
CVE-2015-5119CRITICAL | Adobe Flash Player Use-After-Free VulnerabilityUse-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015. | CVSS9.8v3.1 | EPSS99.3% | PoCs6 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2015-3113CRITICAL | Adobe Flash Player Heap-Based Buffer Overflow VulnerabilityHeap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015. | CVSS9.8v3.1 | EPSS>99.9% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory BufferAdobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. CWE-119Jun 10, 2015 | CVSS10.0v2.0 | EPSS82.7% | PoCs3 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |