CVE-2016-0984
published 2016-02-10CVE-2016-0984: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux…
PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
55.38%
98.9th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air_desktop_runtime | <= 20.0.0.233 | — |
| adobe | air_sdk | <= 20.0.0.233 | — |
| adobe | air_sdk_compiler | <= 20.0.0.233 | — |
| adobe | flash_player | <= 11.2.202.559 | — |
| adobe | flash_player | <= 18.0.0.326 | — |
| adobe | flash_player | <= 20.0.0.272 | — |
| adobe | flash_player | <= 20.0.0.286 | — |
| adobe | flash_player_desktop_runtime | <= 20.0.0.286 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-0984 was exploited in the wild by BlackOasis APT as a zero-day in June 2015, delivering FinSpy payloads via exploit chains. Detections for related FinSpy/Flash exploit activity include PDM:Exploit.Win32.Generic, HEUR:Exploit.SWF.Generic, and HEUR:Exploit.MSOffice.Generic. ↗
- →The Flash exploit (related campaign) uses a NOP sled composed of alternating 0x90 and 0x91 opcodes inside SWF files to evade AV detection of large NOP blocks. Consider scanning SWF files for this byte pattern. ↗
- →The CVE-2016-0984 vulnerability is a use-after-free in Adobe Flash Player's Sound.loadPCMFromByteArray. A dangling pointer is created when a second call with a short ByteArray triggers an exception before the pointer is reset; the pointer is then readable via Sound.extract. Monitor for Flash processes crashing or spawning child processes. ↗
- →The exploit chain delivers a Flash exploit embedded as an ActiveX object inside Office documents (.docx). Hunt for Office processes spawning Flash-related child processes or network connections. ↗
- ·The IOCs from the Kaspersky/Securelist report (IP 89.45.67.107, mo.exe hash, file paths) are primarily associated with the CVE-2017-11292 campaign by BlackOasis, not directly with CVE-2016-0984 itself. They are included because the source explicitly links BlackOasis to CVE-2016-0984 exploit chains delivering FinSpy, and the infrastructure/TTPs overlap. ↗
- ·The exploit-db PoC (39462.zip) is a proof-of-concept for the Sound.loadPCMFromByteArray dangling pointer bug underlying CVE-2016-0984. It demonstrates read-only dangling pointer access, not a full weaponized exploit. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player and AIR Use-After-Free Vulnerability
cisa·2022-05-25·CVSS 8.8
CVE-2016-0984 [HIGH] CWE-416 Adobe Flash Player and AIR Use-After-Free Vulnerability
Vulnerability: Adobe Flash Player and AIR Use-After-Free Vulnerability
Affected: Adobe Flash Player and AIR
Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
Required Action: The impacted products are end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0984
Remediation Due Date: 2022-06-15
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-04
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-0984 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-04
flash-plugin: multiple code execution issues fixed in APSB16-04
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-04
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-0973 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-04
flash-plugin: multiple code execution issues fixed in APSB16-04
Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via a URLLoader.load call, a different vulnerability than CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-04
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-0975 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-04
flash-plugin: multiple code execution issues fixed in APSB16-04
Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code by leveraging improper reference handling, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-04
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-0982 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-04
flash-plugin: multiple code execution issues fixed in APSB16-04
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0983, and CVE-2016-0984.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-04
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-0974 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-04
flash-plugin: multiple code execution issues fixed in APSB16-04
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-04
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-0983 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-04
flash-plugin: multiple code execution issues fixed in APSB16-04
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0984.
VulDB
Adobe Flash Player use after free (RHSA-2016:0166 / EDB-39462)
vuldb·2026-04-23·CVSS 8.8
CVE-2016-0984 [HIGH] Adobe Flash Player use after free (RHSA-2016:0166 / EDB-39462)
A vulnerability described as critical has been identified in Adobe Flash Player. This affects an unknown part. Such manipulation leads to use after free.
This vulnerability is listed as CVE-2016-0984. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-wg97-qrh5-p5pr: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0984 [HIGH] CWE-416 GHSA-wg97-qrh5-p5pr: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
GHSA
GHSA-wqvx-9j6j-hmvp: Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0973 [HIGH] CWE-416 GHSA-wqvx-9j6j-hmvp: Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18
Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via a URLLoader.load call, a different vulnerability than CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
GHSA
GHSA-4xrm-7fmv-6pvg: Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0975 [HIGH] CWE-416 GHSA-4xrm-7fmv-6pvg: Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18
Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code by leveraging improper reference handling, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
GHSA
GHSA-4wx9-j597-qgw7: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0974 [HIGH] CWE-416 GHSA-4wx9-j597-qgw7: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
GHSA
GHSA-x8vc-8rp4-hxjg: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0983 [HIGH] CWE-416 GHSA-x8vc-8rp4-hxjg: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0984.
GHSA
GHSA-4gjw-5fhx-cgrh: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0982 [HIGH] GHSA-4gjw-5fhx-cgrh: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0983, and CVE-2016-0984.
Project0
Life After the Isolated Heap - Project Zero
project_zero·2016-03-01
CVE-2016-0984 Life After the Isolated Heap - Project Zero
Posted by Natalie Silvanovich, Mourner of Lost Exploits
Over the past few months, Adobe has introduced a number of changes to the Flash Player heap with the goal of reducing the exploitability of certain types of vulnerabilities in Flash, especially use-after-frees. I wrote an exploit involving two bugs discovered after the Isolated Heap was implemented to explore how it impacts their exploitability.
The Isolated Heap
The Flash heap, MMgc, is a garbage collected heap that also supports unmanaged fixed allocations. In the past, there have been many exploits in the wild that used certain properties of the heap to aid exploitation. In particular, many exploits used the allocation properties of Vectors to gain read/write access to the entire Flash memory space via heap memory corruption b
OSV
CVE-2016-0975: Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18
osv·2016-02-10·CVSS 8.8
CVE-2016-0975 [HIGH] CVE-2016-0975: Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18
Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code by leveraging improper reference handling, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
OSV
CVE-2016-0984: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-02-10·CVSS 8.8
CVE-2016-0984 [HIGH] CVE-2016-0984: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
OSV
CVE-2016-0983: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-02-10·CVSS 8.8
CVE-2016-0983 [HIGH] CVE-2016-0983: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0984.
OSV
CVE-2016-0982: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-02-10·CVSS 8.8
CVE-2016-0982 [HIGH] CVE-2016-0982: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0983, and CVE-2016-0984.
OSV
CVE-2016-0973: Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18
osv·2016-02-10·CVSS 8.8
CVE-2016-0973 [HIGH] CVE-2016-0973: Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18
Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via a URLLoader.load call, a different vulnerability than CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
OSV
CVE-2016-0974: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-02-10·CVSS 8.8
CVE-2016-0974 [HIGH] CVE-2016-0974: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
VulnCheck
Adobe Flash Player and AIR Use-After-Free Vulnerability
vulncheck·2016·CVSS 8.8
CVE-2016-0984 [HIGH] CWE-416 Adobe Flash Player and AIR Use-After-Free Vulnerability
Adobe Flash Player and AIR Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
Affected: Adobe Flash Player and AIR
Required Action: The impacted products are end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://securelist.com/blackoasis-apt-and-new-targeted-attacks-leveraging-zero-day-exploit/82732/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-15
No detection rules found.
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
- Introduction
- BlackOasis Background
- Attacks Leveraging CVE-2017-11292
- Targeting and Victims
- Conclusions
- Acknowledgements
- References
- Indicators of compromise
Authors
- GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft Offic
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
Introduction
BlackOasis Background
Attacks Leveraging CVE-2017-11292
Payload – mo.exe
Targeting and Victims
Conclusions
Acknowledgements
References
Indicators of compromise
Authors
GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft
Securelist
APT Trends report Q2 2017
blogs_securelist·2017-08-08
APT Trends report Q2 2017
Table of Contents
- Introduction
- Russian-Speaking Actors
- English-Speaking Actors
- Korean-speaking Actors
- Middle Eastern Actors
- Chinese-Speaking Actors
- Best of the rest
- Predictions
- How to keep yourself protected
Authors
- GReAT
## Introduction
Since 2014, Kaspersky Lab’s Global Research and Analysis Team (GReAT) has been providing threat intelligence reports to a wide-range of customers worldwide, leading to the delivery of a full and dedicated private reporting service. Prior to the new service offering, GReAT published research online for the general public in an effort to help combat the ever-increasing threat from nation-state and other advanced actors. Since we began offering a threat intelligence service, all deep technical details on advanced campaigns are first
Securelist
APT Trends report Q2 2017
blogs_securelist·2017-08-08·CVSS 7.8
[HIGH] APT Trends report Q2 2017
Table of Contents
Introduction
Russian-Speaking Actors
English-Speaking Actors
Korean-speaking Actors
Middle Eastern Actors
Chinese-Speaking Actors
Best of the rest
Predictions
How to keep yourself protected
Authors
GReAT
## Introduction
Kaspersky’s Private Threat Intelligence Portal (TIP)
In Q1 of 2017 we published our first APT Trends report , highlighting our top research findings over the last few months. We will continue to publish quarterly reports as a representative snapshot of what has been offered in greater detail in our private reports in order to highlight significant events and findings we feel most users should be aware of. If you would like to learn more about our intelligence reports or request more information for a specific report, readers are encouraged to
Zscaler
Zscaler detects Flash Player Vulnerabilities | 02-16-2016
blogs_zscaler
Zscaler detects Flash Player Vulnerabilities | 02-16-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-04
bugzilla·2016-02-09·CVSS 8.8
CVE-2016-0985 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-04
flash-plugin: multiple code execution issues fixed in APSB16-04
Adobe Security Bulletin APSB16-04 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-04:
These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2016-0985).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, CVE-2016-0984).
These updates resolve a heap buffer overflow vulnerability that could lead to code execution (CVE-2016-0971).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2016-0964, CVE-2016-0965, C
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0166.htmlhttp://www.securitytracker.com/id/1034970https://helpx.adobe.com/security/products/flash-player/apsb16-04.htmlhttps://security.gentoo.org/glsa/201603-07https://www.exploit-db.com/exploits/39462/http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0166.htmlhttp://www.securitytracker.com/id/1034970https://helpx.adobe.com/security/products/flash-player/apsb16-04.htmlhttps://security.gentoo.org/glsa/201603-07https://www.exploit-db.com/exploits/39462/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0984
2016-02-10
Published
2022-05-25
Added to CISA KEV
Exploited in the wild