CVE-2016-7881Use After Free in Adobe Flash Player

CWE-416Use After Free5 documents5 sources
Severity
8.8HIGHNVD
EPSS
5.9%
top 9.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 14

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class when handling conversion to an object. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-78xm-g4fw-g356: Adobe Flash Player versions 232022-05-14
CVEList
CVE-2016-7881: Adobe Flash Player versions 232016-12-15

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-392016-12-13

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-392016-12-13
CVE-2016-7881 — Use After Free in Adobe Flash Player | cvebase