High severity8.8NVD Advisory· Published Mar 12, 2016· Updated May 6, 2026
CVE-2016-1001
CVE-2016-1001
Description
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors.
Affected products
10- cpe:2.3:a:adobe:air_desktop_runtime:*:*:*:*:*:*:*:*Range: <=20.0.0.260
- cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*Range: <=20.0.0.260
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.569
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*range: <=20.0.0.306
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*range: <=20.0.0.306
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*range: <=20.0.0.306
- cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*Range: <=20.2.2.306
- cpe:2.3:o:samsung:x14j_firmware:t-ms14jakucb-1102.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- helpx.adobe.com/security/products/flash-player/apsb16-08.htmlnvdPatchVendor Advisory
- www.exploit-db.com/exploits/39609/nvdExploitThird Party AdvisoryVDB Entry
- lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlnvdBroken LinkMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlnvdBroken LinkMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlnvdBroken LinkMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlnvdBroken LinkMailing ListThird Party Advisory
- www.securitytracker.com/id/1035251nvdBroken LinkThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201603-07nvdThird Party Advisory
News mentions
0No linked articles in our index yet.