CVE-2016-0999
published 2016-03-12CVE-2016-0999: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on…
PriorityP270high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
29.84%
98.0th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 20.0.0.233 | — |
| adobe | air_desktop_runtime | <= 20.0.0.260 | — |
| adobe | air_sdk | <= 20.0.0.260 | — |
| adobe | air_sdk_compiler | <= 20.0.0.260 | — |
| adobe | flash_player | <= 20.0.0.306 | — |
| adobe | flash_player | <= 11.2.202.569 | — |
| adobe | flash_player_desktop_runtime | <= 20.2.2.306 | — |
| samsung | x14j_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for ActionScript calls to AsBroadcaster.initialize() followed immediately by ab.broadcastMessage() with no arguments — this triggers the uninitialized stack parameter access (alloca(0) path). ↗
- →Detect SWF files loaded with a 'num' query parameter in the range 0–31, particularly sequential loads of the same SWF with different num values (e.g., num=15 then num=4), which is characteristic of the PoC stack-shifting technique. ↗
- →Crash/exploit involves conversion of an uninitialized stack value containing a UTF string pattern 'fffff...' — memory forensics or crash dumps showing this pattern in Flash stack frames may indicate exploitation attempts. ↗
- ·The PoC is described as 'finicky' and crash behavior varies by browser and stack state; the num parameter (0–31) must be tuned per target environment, meaning exploitation is not deterministic. ↗
- ·CVE-2016-0999 is one of multiple use-after-free vulnerabilities patched together; the NVD source document references CVE-2016-0990, not CVE-2016-0999 directly — confirm correct CVE mapping before operationalizing detections. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7m8c-j4rm-p9xf: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0987 [HIGH] CWE-416 GHSA-7m8c-j4rm-p9xf: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-289x-vwg3-v978: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1000 [HIGH] CWE-416 GHSA-289x-vwg3-v978: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.
GHSA
GHSA-6cgf-ccqv-hqc5: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0994 [HIGH] CWE-416 GHSA-6cgf-ccqv-hqc5: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-3mx4-h2pg-vf39: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0991 [HIGH] CWE-416 GHSA-3mx4-h2pg-vf39: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-gjfv-9q5r-vp58: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0999 [HIGH] CWE-416 GHSA-gjfv-9q5r-vp58: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
GHSA
GHSA-8p7h-vjm2-xpww: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0997 [HIGH] CWE-416 GHSA-8p7h-vjm2-xpww: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-xvp5-wq6m-9jj9: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0996 [HIGH] CWE-416 GHSA-xvp5-wq6m-9jj9: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-8wv3-4xc3-cq3g: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0998 [HIGH] CWE-416 GHSA-8wv3-4xc3-cq3g: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-3hjw-3fcj-gcqj: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0995 [HIGH] CWE-416 GHSA-3hjw-3fcj-gcqj: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-32v5-69px-96x3: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0988 [HIGH] CWE-416 GHSA-32v5-69px-96x3: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
GHSA
GHSA-gqv9-7grx-4w32: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0990 [HIGH] CWE-416 GHSA-gqv9-7grx-4w32: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0988: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0988 [HIGH] CVE-2016-0988: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0997: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0997 [HIGH] CVE-2016-0997: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0999: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0999 [HIGH] CVE-2016-0999: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
OSV
CVE-2016-0991: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0991 [HIGH] CVE-2016-0991: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0996: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0996 [HIGH] CVE-2016-0996: Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0994: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0994 [HIGH] CVE-2016-0994: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0990: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0990 [HIGH] CVE-2016-0990: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-1000: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-1000 [HIGH] CVE-2016-1000: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.
OSV
CVE-2016-0995: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0995 [HIGH] CVE-2016-0995: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0987: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0987 [HIGH] CVE-2016-0987: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
OSV
CVE-2016-0998: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0998 [HIGH] CVE-2016-0998: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0991 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0998 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-1000 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0987 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0990 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0988 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0995 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0994 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0997 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0996 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0999 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlhttp://www.securityfocus.com/bid/84312http://www.securitytracker.com/id/1035251https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlhttps://security.gentoo.org/glsa/201603-07https://www.exploit-db.com/exploits/39611/http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlhttp://www.securityfocus.com/bid/84312http://www.securitytracker.com/id/1035251https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlhttps://security.gentoo.org/glsa/201603-07https://www.exploit-db.com/exploits/39611/
2016-03-12
Published