CVE-2016-7855

EUVD-2016-8704
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
adobeflash_player
𝑥
≤ 23.0.0.185
adobeflash_player
𝑥
≤ 23.0.0.185
adobeflash_player
𝑥
≤ 23.0.0.185
adobeflash_player
𝑥
≤ 11.2.202.637
adobeflash_player
𝑥
≤ 23.0.0.185
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
precise
Fixed 1:20161026.1-0ubuntu0.12.04.1
released
trusty
Fixed 1:20161026.1-0ubuntu0.14.04.1
released
xenial
Fixed 1:20161026.1-0ubuntu0.16.04.1
released
yakkety
Fixed 1:20161026.1-0ubuntu0.16.10.1
released
flashplugin-nonfree
precise
Fixed 11.2.202.643ubuntu0.12.04.1
released
trusty
Fixed 11.2.202.643ubuntu0.14.04.1
released
xenial
Fixed 11.2.202.643ubuntu0.16.04.1
released
yakkety
Fixed 11.2.202.643ubuntu0.16.10.1
released