Vulnerability Description
Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet Explorer 10 and 11 before 20.0.0.267, Adobe Flash Player for Linux before 11.2.202.559, AIR Desktop Runtime before 20.0.0.233, AIR SDK before 20.0.0.233, AIR SDK & Compiler before 20.0.0.233, AIR for Android before 20.0.0.233.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 20.0.0.235 |
| Apple | Mac Os X | - |
| Microsoft | Windows | - |
| Adobe | Flash Player Extended Support Release | <= 18.0.0.268 |
| Chrome Os | - | |
| Linux | Linux Kernel | - |
| Microsoft | Windows 10 | All versions |
| Microsoft | Windows 8 | All versions |
| Microsoft | Windows 8.1 | All versions |
| Adobe | Flash Player For Linux | <= 11.2.202.554 |
| Adobe | Air | <= 20.0.0.204 |
| Adobe | Air Sdk \& Compiler | <= 20.0.0.204 |
| Apple | Iphone Os | All versions |
| Android | - | |
| Adobe | Air Sdk | <= 20.0.0.204 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2015-2697.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1294580Issue TrackingThird Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2697.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1294580Issue TrackingThird Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlVendor Advisory
FAQ
What is CVE-2016-0959?
CVE-2016-0959 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0....
How severe is CVE-2016-0959?
CVE-2016-0959 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-0959?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Apple Mac Os X, Microsoft Windows, Adobe Flash Player Extended Support Release, Google Chrome Os.