CVE-2018-4871: Adobe Flash Player

High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.

An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Affected products

  • Adobe Flash Player: up to and including 28.0.0.126
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2018-01-09. Last modified 2026-06-17.