All CVEs View on NVD
CVE-2016-4117
CRITICAL9.8
CISA KEV
Published 2016-05-11 · Updated 2026-09-10 · Source psirt@adobe.com
Description
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known-Exploited Vulnerability
Product: Adobe — Flash Player
Name: Adobe Flash Player Arbitrary Code Execution Vulnerability
Date added: 2022-03-03 · Due: 2022-03-24
USED IN RANSOMWARE
Required action: The impacted product is end-of-life and should be disconnected if still in use.
References
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.html
- http://rhn.redhat.com/errata/RHSA-2016-1079.html
- http://www.securityfocus.com/bid/90505
- http://www.securitytracker.com/id/1035826
- https://helpx.adobe.com/security/products/flash-player/apsa16-02.html

