Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
REVIEWED ORIGINAL-SOURCE CLAIMOFFICIAL VENDOR SOURCEREVIEWED 13 SEP 2026

Adobe · EDITORIAL PRIMARY-SOURCE REVIEW

Adobe Flash Player

Adobe Flash Player is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This claim was manually scoped and reviewed against the linked original publisher statement. It applies only to the named release and support phase. Confirm edition, device and contract applicability before acting.

Reviewed 13 Sep 2026.

Product overview

Adobe Flash Player is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • User-facing application functions
  • Local or managed application deployment
  • Vendor-maintained feature and security updates

Typical use

Used by individuals or organizations for the product-specific tasks described by its publisher.

Deployment

Installed on supported endpoints or supplied through a vendor-managed service, depending on the edition.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductAdobe Flash Player
ReleaseFlash Player
End of End of support31 December 2020
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 5 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2014-0502Added 17 Sep 2024

Adobe Flash Player Double Free Vulnerablity

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.

Adobe · Flash PlayerRansomware use: Unknown

CISA entry
CVE-2014-0497Added 17 Sep 2024

Adobe Flash Player Integer Underflow Vulnerablity

Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.

Adobe · Flash PlayerRansomware use: Unknown

CISA entry
CVE-2013-0648Added 17 Sep 2024

Adobe Flash Player Code Execution Vulnerability

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.

Adobe · Flash PlayerRansomware use: Unknown

CISA entry
CVE-2013-0643Added 17 Sep 2024

Adobe Flash Player Incorrect Default Permissions Vulnerability

Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.

Adobe · Flash PlayerRansomware use: Unknown

CISA entry
CVE-2012-5054Added 8 Jun 2022

Adobe Flash Player Integer Overflow Vulnerability

Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.

Adobe · Flash PlayerRansomware use: Unknown

CISA entry
CVE-2012-0767Added 8 Jun 2022

Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability

Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.

Adobe · Flash PlayerRansomware use: Unknown

CISA entry

Showing the 6 most recently added of 36 product-family matches.

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYReady

Adobe Flash Player official lifecycle source

Adobe stopped supporting Flash Player beginning December 31, 2020

Official vendor lifecycle or product-change property. Extracted records require human review.

Original-source claim reviewed 13 Sep 2026

Open official vendor source