← לוח פגיעויות

CVE-2016-4171

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Adobe Flash Player Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
The impacted product is end-of-life and should be disconnected if still in use.

תיאור (מקור, אנגלית)

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
20% (אחוזון 100) נכון ל-24/7/2026

מוצרים מושפעים

adobe: flash player; linux: linux kernel; apple: mac os x; apple: macos; microsoft: windows; google: chrome os; microsoft: windows 8.1; microsoft: windows 10; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation; opensuse: opensuse; suse: linux enterprise desktop; suse: linux enterprise workstation extension

קישורים