CVE-2016-4128
published 2016-06-16CVE-2016-4128: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.81%
88.9th percentile
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 11.2.202.621 | — |
| adobe | flash_player | <= 18.0.0.352 | — |
| adobe | flash_player | <= 21.0.0.242 | — |
| adobe | flash_player_desktop_runtime | <= 21.0.0.242 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-18
vendor_redhat·2016-06-14·CVSS 8.8
CVE-2016-4128 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-18
flash-plugin: multiple code execution issues fixed in APSB16-18
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
GHSA
GHSA-mqhj-hqxg-47h7: Unspecified vulnerability in Adobe Flash Player 21
ghsa_unreviewed·2022-05-13
CVE-2016-4128 [CRITICAL] CWE-787 GHSA-mqhj-hqxg-47h7: Unspecified vulnerability in Adobe Flash Player 21
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6172 pdns: Improper restriction of zone size limit
bugzilla·2016-07-07·CVSS 6.8
CVE-2016-6172 [MEDIUM] CVE-2016-6172 pdns: Improper restriction of zone size limit
CVE-2016-6172 pdns: Improper restriction of zone size limit
It was found that PowerDNS does not implement reasonable restrictions for zone sizes. This allows an explicitly configured primary DNS server for a zone to crash a secondary DNS server, affecting service of other zones hosted on the same secondary server.
CVE request:
http://seclists.org/oss-sec/2016/q3/19
Proposed patch:
https://github.com/sischkg/xfer-limit/blob/master/powerdns-3.4.7-xfer-limit-0.0.1.patch
Discussion:
Created pdns tracking bugs for this issue:
Affects: fedora-all [bug 1353566]
Affects: epel-all [bug 1353567]
---
Upstream issue:
https://github.com/PowerDNS/pdns/issues/4128
The following patches are still under review but should be merged soon:
- Master: https://github.com/PowerDNS/pdns/pull/4133
- 3.
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-18
bugzilla·2016-06-15·CVSS 8.8
CVE-2016-4171 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-18
flash-plugin: multiple code execution issues fixed in APSB16-18
Adobe released a new security advisory for Adobe Flash Player.
A critical vulnerability (CVE-2016-4171) exists in Adobe Flash Player 21.0.0.242 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of a report that an exploit for CVE-2016-4171 exists in the wild, and is being used in limited, targeted attacks. Adobe will address this vulnerability in our monthly security update, which will be available as early as June 16. For the latest information, users may monitor the Adobe Product Security Incident Response Team blog.
https://helpx.adobe.com/security/products/flash-player/ap
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlhttp://www.securitytracker.com/id/1036117https://access.redhat.com/errata/RHSA-2016:1238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083https://helpx.adobe.com/security/products/flash-player/apsb16-18.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlhttp://www.securitytracker.com/id/1036117https://access.redhat.com/errata/RHSA-2016:1238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
2016-06-16
Published