CVE-2019-7096

CWE-416Use After Free6 documents6 sources
Severity
9.8CRITICAL
EPSS
6.8%
top 8.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 24

Description

Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDadobe/flash_player32.0.0.156
CVEListV5adobe/adobe_flash_player32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier versions
Ubuntuflashplugin-nonfree< 32.0.0.171ubuntu0.14.04.1+2

🔴Vulnerability Details

3
GHSA
GHSA-9p2m-7x3f-fh47: Adobe Flash Player versions 322022-05-24
CVEList
CVE-2019-7096: Adobe Flash Player versions 322019-05-23
OSV
CVE-2019-7096: Adobe Flash Player versions 322019-05-23

📋Vendor Advisories

1
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB19-19)2019-04-09

💬Community

1
Bugzilla
CVE-2019-7096 flash-plugin: Arbitrary Code Execution vulnerability (APSB19-19)2019-04-09