CVE-2018-4944
9.8
CRITICAL · CVSS 3.0 · EPSS 8.6% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.63% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-704 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-05-19 |
| Last modified | 2026-06-17 |
Affected (10)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | macos |
| chrome os | |
| linux | linux kernel |
| microsoft | windows |
| microsoft | windows 10 |
| microsoft | windows 8.1 |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
References
- http://www.securityfocus.com/bid/104101
- http://www.securitytracker.com/id/1040840
- https://access.redhat.com/errata/RHSA-2018:1367
- https://helpx.adobe.com/security/products/flash-player/apsb18-16.html
- https://security.gentoo.org/glsa/201806-02
- http://www.securityfocus.com/bid/104101
- http://www.securitytracker.com/id/1040840
- https://access.redhat.com/errata/RHSA-2018:1367
- https://helpx.adobe.com/security/products/flash-player/apsb18-16.html
- https://security.gentoo.org/glsa/201806-02
→ the Explorer · watch your stack · NVD