CVE-2018-5002: Adobe Flash Player Stack-based Buffer Overflow Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-05-23. EPSS: 25.1% chance of exploitation in the next 30 days.

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected products

  • Adobe Flash Player: up to and including 29.0.0.171
  • Adobe Flash Player Desktop Runtime: up to and including 29.0.0.171
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2018-07-09. Last modified 2026-06-17.