CVE-2016-1005
12.03.2016, 15:59
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and memory corruption) via crafted MPEG-4 data, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, and CVE-2016-1002.Enginsight
Vendor | Product | Version |
---|---|---|
adobe | flash_player | 𝑥 ≤ 20.0.0.306 |
adobe | air | 𝑥 ≤ 20.0.0.233 |
adobe | air_sdk | 𝑥 ≤ 20.0.0.260 |
adobe | flash_player | 𝑥 ≤ 11.2.202.569 |
adobe | flash_player_desktop_runtime | 𝑥 ≤ 20.2.2.306 |
adobe | flash_player | 𝑥 ≤ 20.0.0.306 |
adobe | flash_player | 𝑥 ≤ 20.0.0.306 |
adobe | air_desktop_runtime | 𝑥 ≤ 20.0.0.260 |
adobe | air_sdk_\&_compiler | 𝑥 ≤ 20.0.0.260 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||
---|---|---|---|---|---|---|---|
adobe-flashplugin |
| ||||||
flashplugin-nonfree |
|
Common Weakness Enumeration
References