CVE-2016-4171
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Flash Player Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 20% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
adobe: flash player; linux: linux kernel; apple: mac os x; apple: macos; microsoft: windows; google: chrome os; microsoft: windows 8.1; microsoft: windows 10; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation; opensuse: opensuse; suse: linux enterprise desktop; suse: linux enterprise workstation extension
קישורים
- https://helpx.adobe.com/security/products/flash-player/apsa16-03.html Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.html Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsa16-03.html Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.html Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/91184 Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036094 Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2016:1238 Third Party Advisory