CVE-2016-0990
published 2016-03-12CVE-2016-0990: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 20.0.0.233 | — |
| adobe | air_desktop_runtime | <= 20.0.0.260 | — |
| adobe | air_sdk | <= 20.0.0.260 | — |
| adobe | air_sdk_compiler | <= 20.0.0.260 | — |
| adobe | flash_player | <= 20.0.0.306 | — |
| adobe | flash_player | <= 11.2.202.569 | — |
| adobe | flash_player_desktop_runtime | <= 20.2.2.306 | — |
| samsung | x14j_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH