Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Flash_player | — | adobe-air-upgrade-21-0-0-176adobe-flash-upgrade-11-2-202-577-linuxadobe-flash-upgrade-18-0-0-333-macosxadobe-flash-upgrade-18-0-0-333-windowsadobe-flash-upgrade-21-0-0-182-macosxadobe-flash-upgrade-21-0-0-182-windows | Mar 12, 2016 | Mar 10, 2016 |
| Freebsd | freebsd-upgrade-package-linux-c6-flashpluginfreebsd-upgrade-package-linux-f10-flashpluginfreebsd-upgrade-package-linux-c6_64-flashplugin | Dec 10, 2025 | Mar 31, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-www-plugins-adobe-flash | Oct 30, 2017 | Mar 12, 2016 | |
| Suse | — | suse-upgrade-flash-playersuse-upgrade-flash-player-gnomesuse-upgrade-flash-player-kde4 | Mar 11, 2016 | Mar 11, 2016 |
| Ubuntu | ubuntu-upgrade-adobe-flashpluginubuntu-upgrade-flashplugin-nonfree | Nov 19, 2024 | Mar 12, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub