6.5
CVSSv3

CVE-2016-4277

Published: 14/09/2016 Updated: 10/11/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Adobe Flash Player prior to 18.0.0.375 and 19.x up to and including 23.x prior to 23.0.0.162 on Windows and OS X and prior to 11.2.202.635 on Linux allows malicious users to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe flash_player_desktop_runtime

Vendor Advisories

Adobe Flash Player before 1800375 and 19x through 23x before 2300162 on Windows and OS X and before 112202635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278 ...

Github Repositories

CVE-2016-4277 Adobe Flash Player before 1800375 and 19x through 23x before 2300162 on Windows and OS X and before 112202635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278 authentication complexity vector NONE MEDIUM NETWOR

CVE-2016-4278 Adobe Flash Player before 1800375 and 19x through 23x before 2300162 on Windows and OS X and before 112202635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4277 authentication complexity vector NONE MEDIUM NETWOR

CVE-Study CVE id CVSS Type CVE-2017-12762 100 BOF CVE-2017-0561 100 - CVE-2017-11176 100 UAF CVE-2017-8890 100 CVE-2017-7895 100 CVE-2017-3106 93 CVE-2017-3064 93 CVE-2017-0430 93 CVE-2017-0429 93 CVE-2017-0428 93 CVE-2017-0427 93 CVE-2017-0528 93 CVE-2017-0510 93 CVE-2017-0508 93 CVE-2017-0507 93 CVE-2017-0455 93

Recent Articles

Adobe releases updates that resolve 35 Security Vulnerabilities
BleepingComputer • Lawrence Abrams • 14 Sep 2016

Yesterday, Adobe released updates for Adobe Flash, Adobe Digital Editions, and Adobe AIR SDK & Compiler.  When you combine the vulnerabilities patched for the three products, there are 35 exploits fixed, with many of them allowing code execution.
Code execution is when the vulnerability can be exploited to execute commands on the affected computer.  This allows attackers to create specially crafted code that can be inserted onto web sites, which cause a vulnerable visitor to downl...