10

CVE-2016-1019

Warnung
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Desktop Runtime Version <= 21.0.0.197
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwEdition esr Version <= 18.0.0.333
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwPlatform chrome Version <= 21.0.0.197
   Apple ≫ macOS X Version -
   Google ≫ Chrome Os Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwPlatform edge Version <= 21.0.0.197
   Microsoft ≫ Windows 10 Version -
Adobe ≫ Flash Player SwPlatform internet_explorer Version <= 21.0.0.197
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 8.1 Version -
Adobe ≫ Flash Player Version <= 11.2.202.577
   Linux ≫ Linux Kernel Version -
Adobe ≫ Air Desktop Runtime Version <= 21.0.0.176
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Air Sdk Version <= 21.0.0.176
   Apple ≫ iPhone OS Version -
   Apple ≫ macOS X Version -
   Google ≫ Android Version -
   Microsoft ≫ Windows Version -

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Adobe Flash Player Arbitrary Code Execution Vulnerability

Schwachstelle

Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.

Beschreibung

The impacted product is end-of-life and should be disconnected if still in use.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.49% 0.974
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://blogs.adobe.com/psirt/?p=1330
Vendor Advisory
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html
Broken Link
http://www.securityfocus.com/bid/85856
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1035491
Third Party Advisory
Broken Link
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050
Patch
Third Party Advisory
Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsa16-01.html
Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-10.html
Vendor Advisory
https://security.gentoo.org/glsa/201606-08
Third Party Advisory
https://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.html
Broken Link
https://github.com/cisagov/vulnrichment/issues/196
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2016-0610.html
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1019
US Government Resource