High severity8.1NVD Advisory· Published Apr 9, 2016· Updated May 6, 2026
CVE-2016-1006
CVE-2016-1006
Description
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass the ASLR protection mechanism via JIT data.
Affected products
9- cpe:2.3:a:adobe:air_desktop_runtime:*:*:*:*:*:*:*:*Range: <=21.0.0.176
- cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*Range: <=21.0.0.176
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.577
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:*range: <=18.0.0.333
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*Range: <=21.0.0.197
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050nvdPatchThird Party Advisory
- helpx.adobe.com/security/products/flash-player/apsb16-10.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlnvdBroken LinkThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlnvdBroken LinkThird Party Advisory
- rhn.redhat.com/errata/RHSA-2016-0610.htmlnvdThird Party Advisory
- www.securitytracker.com/id/1035509nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.