VDB
CVE-2016-4117
CVE-2016-4117
PUBLISHED
KEV
CVSS 9.800000190734863 CRITICAL
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
EPSS 94.35% · 99.8th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
94.35%
99.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | flashplugin-nonfree | 11.2.202.540ubuntu2, 11.2.202.548ubuntu1, 11.2.202.559ubuntu1 |
| Ubuntu:14.04:LTS | flashplugin-nonfree | 11.2.202.356ubuntu0.14.04.1, 11.2.202.359ubuntu0.14.04.1, * |
Timeline
- Aug 15, 2012 VulnCheck KEV Exploitation
- Sep 1, 2012 VulnCheck KEV Exploitation
- Oct 13, 2015 VulnCheck KEV Exploitation
- Oct 15, 2015 VulnCheck KEV Exploitation
- Dec 15, 2015 VulnCheck KEV Exploitation
- Mar 15, 2016 VulnCheck KEV Exploitation
- Apr 7, 2016 VulnCheck KEV Exploitation
- Apr 28, 2016 VulnCheck KEV Exploitation
- May 8, 2016 VulnCheck KEV Exploitation
- May 11, 2016 CVE Published
- May 11, 2016 VulnCheck KEV Exploitation
- May 12, 2016 PoC Published
References
- https://ubuntu.com/security/CVE-2016-4117 third-party-advisory
- https://helpx.adobe.com/security/products/flash-player/apsa16-02.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-4117 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory
- Vulnérabilité dans Adobe Flash Player advisory