CVE-2016-7855

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
adobeCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
adobeflash_player
𝑥
≤ 23.0.0.185
adobeflash_player
𝑥
≤ 23.0.0.185
adobeflash_player
𝑥
≤ 23.0.0.185
adobeflash_player
𝑥
≤ 11.2.202.637
adobeflash_player
𝑥
≤ 23.0.0.185
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
yakkety
Fixed 1:20161026.1-0ubuntu0.16.10.1
released
xenial
Fixed 1:20161026.1-0ubuntu0.16.04.1
released
trusty
Fixed 1:20161026.1-0ubuntu0.14.04.1
released
precise
Fixed 1:20161026.1-0ubuntu0.12.04.1
released
flashplugin-nonfree
yakkety
Fixed 11.2.202.643ubuntu0.16.10.1
released
xenial
Fixed 11.2.202.643ubuntu0.16.04.1
released
trusty
Fixed 11.2.202.643ubuntu0.14.04.1
released
precise
Fixed 11.2.202.643ubuntu0.12.04.1
released