CRITICAL · 9.8

CVE-2016-0959

Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0....

Vulnerability Description

Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet Explorer 10 and 11 before 20.0.0.267, Adobe Flash Player for Linux before 11.2.202.559, AIR Desktop Runtime before 20.0.0.233, AIR SDK before 20.0.0.233, AIR SDK & Compiler before 20.0.0.233, AIR for Android before 20.0.0.233.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AdobeFlash Player<= 20.0.0.235
AppleMac Os X-
MicrosoftWindows-
AdobeFlash Player Extended Support Release<= 18.0.0.268
GoogleChrome Os-
LinuxLinux Kernel-
MicrosoftWindows 10All versions
MicrosoftWindows 8All versions
MicrosoftWindows 8.1All versions
AdobeFlash Player For Linux<= 11.2.202.554
AdobeAir<= 20.0.0.204
AdobeAir Sdk \& Compiler<= 20.0.0.204
AppleIphone OsAll versions
GoogleAndroid-
AdobeAir Sdk<= 20.0.0.204

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-0959?

CVE-2016-0959 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0....

How severe is CVE-2016-0959?

CVE-2016-0959 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-0959?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Apple Mac Os X, Microsoft Windows, Adobe Flash Player Extended Support Release, Google Chrome Os.