Flash Player
Vendor:
First CVE: Dec 31, 2005 · Active for 20 years
1,084
Total CVEs
More Total CVEs than 100% of tracked products
67.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
3.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Flash Player over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Oct 14, 2020
2,109 days ago
CVE Severity & Scoring
Flash Player1,084 CVEs
10%
86%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (1.3%)
Network406 (37.5%)
Unknown664 (61.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low392 (36.2%)
High28 (2.6%)
Unknown664 (61.3%)
User Interaction
None61 (5.6%)
Unknown664 (61.3%)
Required359 (33.1%)
Privileges Required
Low1 (0.1%)
High0 (0.0%)
None419 (38.7%)
Unknown664 (61.3%)
Top CVEs
Signals from CVEs in this product scope (1084 CVEs).
1,084 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4117CRITICAL Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016. | May 11, 2016 | 9.8 | 98 | YES | YES |
CVE-2015-5122CRITICAL Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1 | Jul 14, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-5119CRITICAL Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows | Jul 8, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-3113CRITICAL Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack | Jun 23, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-0313CRITICAL Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta | Feb 2, 2015 | 9.8 | 98 | YES | YES |
CVE-2014-0497CRITICAL Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta | Feb 5, 2014 | 9.8 | 98 | YES | YES |
CVE-2011-0611HIGH Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib | Apr 13, 2011 | 8.8 | 98 | YES | YES |
CVE-2015-3043CRITICAL Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or caus | Apr 14, 2015 | 9.8 | 97 | YES | YES |
CVE-2015-0311CRITICAL Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote a | Jan 23, 2015 | 9.8 | 97 | YES | YES |
CVE-2012-0754HIGH Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Andro | Feb 16, 2012 | 8.1 | 97 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (1084 CVEs).
CISA KEV
36 CVEs
3.3% of CVEs· 97th percentile
Metasploit
29 CVEs
2.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
180 CVEs
16.6% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (1084 CVEs).
Media Mentions
Signals from CVEs in this product scope (1084 CVEs).
Top CNAs Publishing CVEs For Flash Player
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| mx_2004 | 3 | 7.1 | 11.7% | 0 | 0 |
| cs4 | 4 | 7.2 | 12.4% | 0 | 1 |
| cs3 | 5 | 7.6 | 11.7% | 0 | 1 |
| 9.125.0 | 69 | 8.8 | 10.3% | 0 | 4 |
| 9.0.9.0 | 7 | 8.5 | 5.4% | 0 | 0 |
| 9.0.8.0 | 4 | 8.6 | 5.3% | 0 | 0 |
| 9.0.48.0 | 115 | 8.5 | 9.6% | 0 | 8 |
| 9.0.47.0 | 120 | 8.6 | 9.5% | 0 | 8 |
| 9.0.45.0 | 121 | 8.5 | 9.6% | 0 | 9 |
| 9.0.31.0 | 121 | 8.6 | 9.9% | 0 | 9 |
| 9.0.31 | 109 | 8.6 | 9.8% | 0 | 6 |
| 9.0.283.0 | 54 | 8.9 | 8.9% | 0 | 2 |
| 9.0.28.0 | 121 | 8.4 | 9.7% | 0 | 9 |
| 9.0.280 | 7 | 8.5 | 5.4% | 0 | 0 |
| 9.0.28 | 120 | 8.6 | 9.8% | 0 | 8 |
| 9.0.277.0 | 54 | 8.9 | 8.9% | 0 | 2 |
| 9.0.262.0 | 85 | 8.9 | 8.2% | 0 | 2 |
| 9.0.260.0 | 94 | 8.8 | 9.3% | 0 | 4 |
| 9.0.246.0 | 94 | 8.8 | 9.3% | 0 | 4 |
| 9.0.20.0 | 121 | 8.6 | 9.9% | 0 | 9 |