VDB
CVE-2016-7855
CVE-2016-7855
PUBLISHED
KEV
CVSS 8.800000190734863 HIGH
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
EPSS 25.20% · 97.7th percentile
Risk Scores
CVSS 3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
25.20%
97.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | flashplugin-nonfree | 11.2.202.540ubuntu2, 11.2.202.548ubuntu1, 11.2.202.559ubuntu1 |
| Ubuntu:14.04:LTS | flashplugin-nonfree | 11.2.202.406ubuntu0.14.04.2, 11.2.202.411ubuntu0.14.04.1, 11.2.202.438ubuntu0.14.04.1 |
Timeline
- Jan 19, 1970 VulnCheck XDB Entry
- Jul 5, 2015 VulnCheck KEV Exploitation
- Jul 21, 2015 VulnCheck KEV Exploitation
- Aug 10, 2015 VulnCheck KEV Exploitation
- Feb 3, 2016 VulnCheck KEV Exploitation
- Oct 26, 2016 PoC Published
- Oct 27, 2016 CVE Published
- Jan 9, 2017 VulnCheck KEV Exploitation
- Feb 4, 2018 VulnCheck KEV Exploitation
- Jun 20, 2018 VulnCheck KEV Exploitation
- Sep 5, 2018 VulnCheck KEV Exploitation
- Sep 1, 2019 VulnCheck KEV Exploitation
References
- https://ubuntu.com/security/CVE-2016-7855 third-party-advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-36.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-7855 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory
- Vulnérabilité dans Microsoft Windows advisory