CVE-2016-7871Out-of-bounds Write in Adobe Flash Player

Severity
8.8HIGHNVD
EPSS
2.8%
top 13.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 14

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Worker class. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wjx6-c3cr-2hp8: Adobe Flash Player versions 232022-05-14
CVEList
CVE-2016-7871: Adobe Flash Player versions 232016-12-15

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-392016-12-13

🕵️Threat Intelligence

1
Unit42
Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures2016-12-16

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-392016-12-13
CVE-2016-7871 — Out-of-bounds Write in Adobe | cvebase