CVE Vulnerabilities

CVE-2016-4117

Published: May 11, 2016 | Modified: Nov 17, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

Affected Software

NameVendorStart VersionEnd Version
Flash_playerAdobe*21.0.0.226 (including)
Red Hat Enterprise Linux 5 SupplementaryRedHatflash-plugin-0:11.2.202.621-1.el5*
Red Hat Enterprise Linux 6 SupplementaryRedHatflash-plugin-0:11.2.202.621-1.el6_8*
Adobe-flashpluginUbuntudevel*
Adobe-flashpluginUbuntuprecise*
Adobe-flashpluginUbuntutrusty*
Adobe-flashpluginUbuntuwily*
Adobe-flashpluginUbuntuxenial*
Flashplugin-nonfreeUbuntudevel*
Flashplugin-nonfreeUbuntuesm-apps/xenial*
Flashplugin-nonfreeUbuntuprecise*
Flashplugin-nonfreeUbuntutrusty*
Flashplugin-nonfreeUbuntuwily*
Flashplugin-nonfreeUbuntuxenial*

References