9.8
CVSSv3

CVE-2016-4273

Published: 13/10/2016 Updated: 18/11/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 890
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Flash Player prior to 18.0.0.382 and 19.x up to and including 23.x prior to 23.0.0.185 on Windows and OS X and prior to 11.2.202.637 on Linux allows malicious users to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989, and CVE-2016-6990.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe flash_player_desktop_runtime

Vendor Advisories

Synopsis Critical: flash-plugin security update Type/Severity Security Advisory: Critical Topic An update for flash-plugin is now available for Red Hat Enterprise Linux 5Supplementary and Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact ofCr ...

Exploits

##################################################################################### # Application: Adobe Flash Player # Platforms: Windows,OSX # Versions: 2300162 and earlier # Author: Francis Provencher of COSIG # Website: cosiggouvqcca/en/advisory/ # Twitter: @COSIG_ # Date: October 11, 2016 # CVE-2016-4273 # COSIG-2016-35 ##### ...

Github Repositories

CVE-2016-6982 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989

CVE-2016-6990 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986

CVE-2016-6986 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6989

CVE-2016-4273 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989

CVE-2016-6989 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986

CVE-2016-6984 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6983, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989

CVE-2016-6983 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989

CVE-2016-6985 Adobe Flash Player before 1800382 and 19x through 23x before 2300185 on Windows and OS X and before 112202637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6986, CVE-2016-6989

CVE-Study CVE id CVSS Type CVE-2017-12762 100 BOF CVE-2017-0561 100 - CVE-2017-11176 100 UAF CVE-2017-8890 100 CVE-2017-7895 100 CVE-2017-3106 93 CVE-2017-3064 93 CVE-2017-0430 93 CVE-2017-0429 93 CVE-2017-0428 93 CVE-2017-0427 93 CVE-2017-0528 93 CVE-2017-0510 93 CVE-2017-0508 93 CVE-2017-0507 93 CVE-2017-0455 93

Recent Articles

Adobe releases updates that resolve 84 Security Vulnerabilities
BleepingComputer • Lawrence Abrams • 11 Oct 2016

Today, Adobe released security updates for Adobe Flash Player, Adobe Acrobat and Reader, and Creative Cloud Desktop. When you combine the vulnerabilities patched for the three products, there are 84 exploits fixed, with many of them being labeled as Critical, because they allow code execution.
Code execution is when the vulnerability can be exploited to execute commands on the affected computer.  This allows attackers to create specially crafted code that can be inserted onto web si...