935
VMScore

CVE-2016-1011

Published: 09/04/2016 Updated: 26/01/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in Adobe Flash Player prior to 18.0.0.343 and 19.x up to and including 21.x prior to 21.0.0.213 on Windows and OS X and prior to 11.2.202.616 on Linux allows malicious users to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe flash_player_desktop_runtime

adobe air_desktop_runtime

adobe air_sdk

adobe air_sdk_\\&_compiler

Vendor Advisories

Use-after-free vulnerability in Adobe Flash Player before 1800343 and 19x through 21x before 2100213 on Windows and OS X and before 112202616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031 ...

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=759 There is a use-after-free in MovieClipduplicateMovieClipIf an action associated with the MovieClip frees the clip provided as the initObject parameter to the call, it will be used after it is freedA PoC is attached Proof of Concept: githubcom/offensive-security/ex ...