CVE-2016-4155
published 2016-06-16CVE-2016-4155: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.39%
90.2th percentile
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 11.2.202.621 | — |
| adobe | flash_player | <= 18.0.0.352 | — |
| adobe | flash_player | <= 21.0.0.242 | — |
| adobe | flash_player_desktop_runtime | <= 21.0.0.242 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-18
vendor_redhat·2016-06-14·CVSS 8.8
CVE-2016-4155 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-18
flash-plugin: multiple code execution issues fixed in APSB16-18
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
GHSA
GHSA-wphc-jq7r-f4wr: Unspecified vulnerability in Adobe Flash Player 21
ghsa_unreviewed·2022-05-13
CVE-2016-4155 [HIGH] CWE-787 GHSA-wphc-jq7r-f4wr: Unspecified vulnerability in Adobe Flash Player 21
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
No detection rules found.
No public exploits indexed.
HackerOne
Adobe Flash Player ShimContentResolver(resolverType=1) class Memory Corruption Vulnerability
hackerone·2019-11-12·CVSS 8.8
[HIGH] Adobe Flash Player ShimContentResolver(resolverType=1) class Memory Corruption Vulnerability
Adobe Flash Player ShimContentResolver(resolverType=1) class Memory Corruption Vulnerability
I. Summary
Adobe Flash Player is prone to a vulnerability which leads to memory corruption because of improper validation of ShimContentResolver.resolve().
II. Description
Normally, resolve() should validate its parameter with canResolve() and returns error in AS3 level if anything goes wrong.
However, if ShimContentResolver is constructed with resolverType=1, then invoking resolve() with invalid Opportunity instance, some inner fields of ShimContentResolver will be absent, which will cause a memory crash.
III. Credit
Wen Guanxing from Pangu LAB is credited for this vulnerability.
It has been assigned by Adobe as CVE-2016-4155.
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-18
bugzilla·2016-06-15·CVSS 8.8
CVE-2016-4171 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-18
flash-plugin: multiple code execution issues fixed in APSB16-18
Adobe released a new security advisory for Adobe Flash Player.
A critical vulnerability (CVE-2016-4171) exists in Adobe Flash Player 21.0.0.242 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of a report that an exploit for CVE-2016-4171 exists in the wild, and is being used in limited, targeted attacks. Adobe will address this vulnerability in our monthly security update, which will be available as early as June 16. For the latest information, users may monitor the Adobe Product Security Incident Response Team blog.
https://helpx.adobe.com/security/products/flash-player/ap
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlhttp://www.securitytracker.com/id/1036117https://access.redhat.com/errata/RHSA-2016:1238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083https://helpx.adobe.com/security/products/flash-player/apsb16-18.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlhttp://www.securitytracker.com/id/1036117https://access.redhat.com/errata/RHSA-2016:1238https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
2016-06-16
Published