Adobe Flash Player Double Free Vulnerablity
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
CISA entryAdobe · EDITORIAL PRIMARY-SOURCE REVIEW
Adobe Flash Player is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This claim was manually scoped and reviewed against the linked original publisher statement. It applies only to the named release and support phase. Confirm edition, device and contract applicability before acting.
Reviewed 13 Sep 2026.
Adobe Flash Player is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used by individuals or organizations for the product-specific tasks described by its publisher.
Installed on supported endpoints or supplied through a vendor-managed service, depending on the edition.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Adobe Flash Player |
|---|---|
| Release | Flash Player |
| End of End of support | 31 December 2020 |
| Date precision | Day |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
CISA entryAdobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
CISA entryAdobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.
CISA entryAdobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.
CISA entryAdobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.
CISA entryAdobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.
CISA entryShowing the 6 most recently added of 36 product-family matches.
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Adobe stopped supporting Flash Player beginning December 31, 2020
Official vendor lifecycle or product-change property. Extracted records require human review.
Open official vendor source