CVE-2016-7892
high · 8.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product is end-of-life and should be disconnected if still in use.
Added 2022-03-25Remediation due 2022-04-15
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
8.8
CVSS
18.8%
EPSS (exploit prob.)
97th
EPSS percentile
2016-12-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | flash_player_desktop_runtime | <= 23.0.0.207 |
| apple | mac_os_x | all versions |
| microsoft | windows | all versions |
| adobe | flash_player | <= 23.0.0.207 |
| adobe | flash_player | <= 23.0.0.207 |
| microsoft | windows_10 | all versions |
| microsoft | windows_8.1 | all versions |
| adobe | flash_player | <= 23.0.0.207 |
| apple | mac_os_x | all versions |
| chrome_os | all versions | |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
| adobe | flash_player | <= 11.2.202.644 |
| linux | linux_kernel | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00064.html
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00112.html
- http://rhn.redhat.com/errata/RHSA-2016-2947.html
- http://www.securityfocus.com/bid/94877
- http://www.securitytracker.com/id/1037442
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-154
- https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
- https://security.gentoo.org/glsa/201701-17
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00064.html
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00112.html
- http://rhn.redhat.com/errata/RHSA-2016-2947.html
- http://www.securityfocus.com/bid/94877
- http://www.securitytracker.com/id/1037442
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-154
- https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
- https://security.gentoo.org/glsa/201701-17
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7892
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-7892