5
CVSSv2

CVE-2016-4277

Published: 14/09/2016 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Adobe Flash Player prior to 18.0.0.375 and 19.x through 23.x prior to 23.0.0.162 on Windows and OS X and prior to 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278.

Affected Products

Vendor Product Versions
AdobeFlash Player11.2.202.632, 18.0.0.366, 22.0.0.211

Vendor Advisories

Adobe Flash Player before 1800375 and 19x through 23x before 2300162 on Windows and OS X and before 112202635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278 ...

Github Repositories

CVE-Study CVE id CVSS Type CVE-2017-12762 100 BOF CVE-2017-0561 100 - CVE-2017-11176 100 UAF CVE-2017-8890 100 CVE-2017-7895 100 CVE-2017-3106 93 CVE-2017-3064 93 CVE-2017-0430 93 CVE-2017-0429 93 CVE-2017-0428 93 CVE-2017-0427 93 CVE-2017-0528 93 CVE-2017-0510 93 CVE-2017-0508 93 CVE-2017-0507 93 CVE-2017-0455 93

Recent Articles

Adobe releases updates that resolve 35 Security Vulnerabilities
BleepingComputer • Lawrence Abrams • 14 Sep 2016

Yesterday, Adobe released updates for Adobe Flash, Adobe Digital Editions, and Adobe AIR SDK & Compiler.  When you combine the vulnerabilities patched for the three products, there are 35 exploits fixed, with many of them allowing code execution.
Code execution is when the vulnerability can be exploited to execute commands on the affected computer.  This allows attackers to create specially crafted code that can be inserted onto web sites, which cause a vulnerable visitor to downl...