VDB
CVE-2016-4171
CVE-2016-4171
PUBLISHED
KEV
CVSS 9.800000190734863 CRITICAL
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
EPSS 20.06% · 97.3th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
20.06%
97.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | flashplugin-nonfree | 0, 11.2.202.327ubuntu0.13.10.1, 11.2.202.341ubuntu1 |
| Ubuntu:16.04:LTS | flashplugin-nonfree | 0, 11.2.202.540ubuntu2, 11.2.202.548ubuntu1 |
Timeline
- Apr 13, 2011 VulnCheck KEV Exploitation
- Jan 1, 2012 VulnCheck KEV Exploitation
- Mar 1, 2012 VulnCheck KEV Exploitation
- Jul 2, 2012 VulnCheck KEV Exploitation
- Sep 1, 2012 VulnCheck KEV Exploitation
- Nov 16, 2012 VulnCheck KEV Exploitation
- Jan 30, 2013 VulnCheck KEV Exploitation
- Jan 23, 2015 VulnCheck KEV Exploitation
- Jan 27, 2015 VulnCheck KEV Exploitation
- Mar 12, 2015 VulnCheck KEV Exploitation
- Apr 27, 2015 VulnCheck KEV Exploitation
- Aug 14, 2015 VulnCheck KEV Exploitation
References
- https://ubuntu.com/security/CVE-2016-4171 third-party-advisory
- https://helpx.adobe.com/security/products/flash-player/apsa16-03.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-4171 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory
- Vulnérabilité dans Adobe Flash Player advisory