Flash Player Desktop Runtime
Vendor:
First CVE: Oct 15, 2014 · Active for 11 years
294
Total CVEs
More Total CVEs than 100% of tracked products
42.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.7
Avg CVSS
Higher Avg CVSS than 78% of tracked products
2.7%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Flash Player Desktop Runtime over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 15, 2014
11 years ago
Most Recent CVE
Jun 12, 2020
2,233 days ago
CVE Severity & Scoring
Flash Player Desktop Runtime294 CVEs
89%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (0.7%)
Network289 (98.3%)
Unknown3 (1.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low289 (98.3%)
High2 (0.7%)
Unknown3 (1.0%)
User Interaction
None22 (7.5%)
Unknown3 (1.0%)
Required269 (91.5%)
Privileges Required
Low1 (0.3%)
High0 (0.0%)
None290 (98.6%)
Unknown3 (1.0%)
Top CVEs
Signals from CVEs in this product scope (294 CVEs).
294 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5122CRITICAL Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1 | Jul 14, 2015 | 9.8 | 98 | YES | YES |
CVE-2016-0984HIGH Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0 | Feb 10, 2016 | 8.8 | 92 | YES | YES |
CVE-2014-0569HIGH Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adob | Oct 15, 2014 | 9.3 | 91 | NO | YES |
CVE-2016-1019CRITICAL Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as ex | Apr 7, 2016 | 9.8 | 78 | YES | NO |
CVE-2018-5002HIGH Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context o | Jul 9, 2018 | 7.8 | 76 | YES | NO |
CVE-2015-5123CRITICAL Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0 | Jul 14, 2015 | 9.8 | 76 | YES | NO |
CVE-2016-1010HIGH Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, | Mar 12, 2016 | 8.8 | 71 | YES | NO |
CVE-2017-11292HIGH Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. | Oct 22, 2017 | 8.8 | 69 | YES | NO |
CVE-2016-7892HIGH Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could | Dec 15, 2016 | 8.8 | 68 | YES | NO |
CVE-2016-4228HIGH Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers t | Jul 13, 2016 | 8.8 | 57 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (294 CVEs).
CISA KEV
8 CVEs
2.7% of CVEs· 96th percentile
Metasploit
2 CVEs
0.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
44 CVEs
15.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (294 CVEs).
Media Mentions
Signals from CVEs in this product scope (294 CVEs).
Top CNAs Publishing CVEs For Flash Player Desktop Runtime
Top CWEs
Versions
No cataloged versions.