9.3

CVE-2016-4166

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Desktop Runtime Version <= 21.0.0.242
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwEdition esr Version <= 18.0.0.352
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwPlatform chrome Version <= 21.0.0.242
   Apple ≫ macOS X Version -
   Google ≫ Chrome Os Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player SwPlatform edge Version <= 21.0.0.242
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 8.1 Version -
Adobe ≫ Flash Player SwPlatform internet_explorer Version <= 21.0.0.242
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 8.1 Version -
Adobe ≫ Flash Player Version <= 11.2.202.621
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.94% 0.891
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html
Broken Link
http://www.securitytracker.com/id/1036117
Third Party Advisory
Broken Link
VDB Entry
https://access.redhat.com/errata/RHSA-2016:1238
Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083
Patch
Third Party Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
Patch
Vendor Advisory