CVE-2016-4117
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Flash Player Arbitrary Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 94% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
adobe: flash player; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux server from rhui; redhat: enterprise linux workstation; opensuse: evergreen; opensuse: opensuse; suse: linux enterprise desktop; suse: linux enterprise workstation extension
קישורים
- https://helpx.adobe.com/security/products/flash-player/apsa16-02.html Broken LinkVendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsa16-02.html Broken LinkVendor Advisory
- https://www.exploit-db.com/exploits/46339/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46339/ ExploitThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.html Mailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1079.html Third Party Advisory
- http://www.securityfocus.com/bid/90505 Broken LinkThird Party AdvisoryVDB Entry