Flex
Vendor:
First CVE: Apr 9, 2008 · Active for 18 years
15
Total CVEs
More Total CVEs than 92% of tracked products
7.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Flex over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2008
18 years ago
Most Recent CVE
Jul 31, 2009
6,202 days ago
CVE Severity & Scoring
Flex15 CVEs
40%
60%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown15 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown15 (100.0%)
User Interaction
None0 (0.0%)
Unknown15 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown15 (100.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6019HIGH Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript | Apr 9, 2008 | 9.3 | 66 | NO | YES |
CVE-2009-1869HIGH Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows a | Jul 31, 2009 | 9.3 | 50 | NO | YES |
CVE-2009-0520HIGH Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows rem | Feb 26, 2009 | 9.3 | 50 | NO | YES |
CVE-2009-1868HIGH Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application | Jul 31, 2009 | 9.3 | 48 | NO | YES |
CVE-2009-0519HIGH Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly exe | Feb 26, 2009 | 9.3 | 29 | NO | NO |
CVE-2009-1866HIGH Stack-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (applicatio | Jul 31, 2009 | 9.3 | 28 | NO | NO |
CVE-2009-1864HIGH Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application | Jul 31, 2009 | 9.3 | 28 | NO | NO |
CVE-2009-1865HIGH Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute ar | Jul 31, 2009 | 9.3 | 27 | NO | NO |
CVE-2009-1863HIGH Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application | Jul 31, 2009 | 9.3 | 27 | NO | NO |
CVE-2009-1870MEDIUM Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF fil | Jul 31, 2009 | 4.9 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
26.7% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Flex
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.1 | 1 | 4.3 | 2.7% | 0 | 0 |
| 3.0 | 14 | 7.7 | 13.4% | 0 | 4 |