9.3
CVE-2016-7859
- EPSS 7.04%
- Veröffentlicht 08.11.2016 17:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player For Linux Version <= 11.2.202.643
Adobe ≫ Flash Player SwPlatform chrome Version <= 23.0.0.205
Adobe ≫ Flash Player SwPlatform edge Version <= 23.0.0.205
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 1511
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version - HwPlatform x64
Microsoft ≫ Windows 10 Version 1511
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version - HwPlatform x64
Adobe ≫ Flash Player SwPlatform internet_explorer Version <= 23.0.0.205
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 1511
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version - HwPlatform x64
Microsoft ≫ Windows 10 Version 1511
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version - HwPlatform x64
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.04% | 0.934 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
http://rhn.redhat.com/errata/RHSA-2016-2676.html
http://www.securityfocus.com/bid/94153
http://www.securitytracker.com/id/1037240
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-141
https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
https://security.gentoo.org/glsa/201611-18
http://www.zerodayinitiative.com/advisories/ZDI-16-602