CVE-2016-4287Integer Overflow or Wraparound in Adobe Flash Player

Severity
8.8HIGHNVD
EPSS
7.7%
top 8.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 14

Description

Integer overflow in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDadobe/flash_player11.2.202.632+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v3x4-9vpx-6mp3: Integer overflow in Adobe Flash Player before 182022-05-14
CVEList
CVE-2016-4287: Integer overflow in Adobe Flash Player before 182016-09-14

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-292016-09-13

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-292016-09-13
CVE-2016-4287 — Integer Overflow or Wraparound in Adobe | cvebase