9.3

CVE-2016-4151

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Desktop Runtime Version <= 21.0.0.242
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version <= 11.2.202.621
   Linux ≫ Linux Kernel Version -
Adobe ≫ Flash Player SwEdition esr Version <= 18.0.0.352
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwPlatform edge Version <= 21.0.0.242
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 8.1 Version -
Adobe ≫ Flash Player SwPlatform internet_explorer Version <= 21.0.0.242
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 8.1 Version -
Adobe ≫ Flash Player SwPlatform chrome Version <= 21.0.0.242
   Apple ≫ macOS X Version -
   Google ≫ Chrome Os Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.39% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html
Third Party Advisory
Broken Link
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html
Third Party Advisory
Broken Link
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html
Third Party Advisory
Broken Link
Mailing List
http://www.securitytracker.com/id/1036117
Third Party Advisory
Broken Link
VDB Entry
https://access.redhat.com/errata/RHSA-2016:1238
Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083
Patch
Third Party Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
Patch
Vendor Advisory