CVE-2016-0997
published 2016-03-12CVE-2016-0997: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on…
PriorityP270high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
29.80%
98.0th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 20.0.0.233 | — |
| adobe | air_desktop_runtime | <= 20.0.0.260 | — |
| adobe | air_sdk | <= 20.0.0.260 | — |
| adobe | air_sdk_compiler | <= 20.0.0.260 | — |
| adobe | flash_player | <= 20.0.0.306 | — |
| adobe | flash_player | <= 11.2.202.569 | — |
| adobe | flash_player_desktop_runtime | <= 20.2.2.306 | — |
| samsung | x14j_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger involves calling MovieClip.swapDepths() with no arguments in ActionScript, causing alloca(0) to allocate an uninitialized 16-byte stack region that is subsequently accessed as a parameter. ↗
- →Exploit relies on a URL query parameter 'num' (0–31) to shift the native stack layout; varying this value produces crashes across different browser/Flash combinations. ↗
- →Crash sequence involves loading the malicious SWF twice in quick succession with different 'num' values (e.g., num=15 then num=4); monitor for rapid repeated SWF loads with varying query strings. ↗
- →The uninitialized stack memory contains a recognizable UTF string pattern ('fffff...') that may appear in crash dumps or memory forensics, aiding post-exploitation identification. ↗
- ·The exploit is highly version-sensitive and described as 'finicky'; the specific stack layout and crash behavior depend on the exact Flash Player build in use. ↗
- ·CVE-2016-0997 is listed as one of multiple distinct use-after-free vulnerabilities sharing the same advisory; detections should not conflate it with CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, or CVE-2016-1000. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7m8c-j4rm-p9xf: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0987 [HIGH] CWE-416 GHSA-7m8c-j4rm-p9xf: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-289x-vwg3-v978: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1000 [HIGH] CWE-416 GHSA-289x-vwg3-v978: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.
GHSA
GHSA-6cgf-ccqv-hqc5: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0994 [HIGH] CWE-416 GHSA-6cgf-ccqv-hqc5: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-3mx4-h2pg-vf39: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0991 [HIGH] CWE-416 GHSA-3mx4-h2pg-vf39: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-gjfv-9q5r-vp58: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0999 [HIGH] CWE-416 GHSA-gjfv-9q5r-vp58: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
GHSA
GHSA-8p7h-vjm2-xpww: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0997 [HIGH] CWE-416 GHSA-8p7h-vjm2-xpww: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-xvp5-wq6m-9jj9: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0996 [HIGH] CWE-416 GHSA-xvp5-wq6m-9jj9: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-8wv3-4xc3-cq3g: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0998 [HIGH] CWE-416 GHSA-8wv3-4xc3-cq3g: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-3hjw-3fcj-gcqj: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0995 [HIGH] CWE-416 GHSA-3hjw-3fcj-gcqj: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-32v5-69px-96x3: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0988 [HIGH] CWE-416 GHSA-32v5-69px-96x3: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-gqv9-7grx-4w32: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0990 [HIGH] CWE-416 GHSA-gqv9-7grx-4w32: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0988: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0988 [HIGH] CVE-2016-0988: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0997: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0997 [HIGH] CVE-2016-0997: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0999: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0999 [HIGH] CVE-2016-0999: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
OSV
CVE-2016-0991: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0991 [HIGH] CVE-2016-0991: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0996: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0996 [HIGH] CVE-2016-0996: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0994: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0994 [HIGH] CVE-2016-0994: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0990: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0990 [HIGH] CVE-2016-0990: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-1000: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-1000 [HIGH] CVE-2016-1000: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.
OSV
CVE-2016-0995: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0995 [HIGH] CVE-2016-0995: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0987: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0987 [HIGH] CVE-2016-0987: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0998: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0998 [HIGH] CVE-2016-0998: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0991 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0998 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-1000 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0987 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0990 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0988 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0995 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0994 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0997 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0996 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0999 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlhttp://www.securityfocus.com/bid/84312http://www.securitytracker.com/id/1035251https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlhttps://security.gentoo.org/glsa/201603-07https://www.exploit-db.com/exploits/39613/http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlhttp://www.securityfocus.com/bid/84312http://www.securitytracker.com/id/1035251https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlhttps://security.gentoo.org/glsa/201603-07https://www.exploit-db.com/exploits/39613/
2016-03-12
Published