High severity8.8NVD Advisory· Published Apr 9, 2016· Updated Jun 17, 2026
CVE-2016-1011
CVE-2016-1011
Description
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- cpe:2.3:a:adobe:air_desktop_runtime:*:*:*:*:*:*:*:*Range: <=21.0.0.176
- cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*Range: <=21.0.0.176
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.577
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:*range: <=18.0.0.333
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*range: <=21.0.0.197
- (no CPE)range: <18.0.0.343 / >=19.0 <21.0.0.213 / <11.2.202.616
- cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*Range: <=21.0.0.197
- osv-coords4 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1
< 11.2.202.621-130.1+ 3 more
- (no CPE)range: < 11.2.202.621-130.1
- (no CPE)range: < 11.2.202.621-130.1
- (no CPE)range: < 11.2.202.621-130.1
- (no CPE)range: < 11.2.202.621-130.1
Patches
Vulnerability mechanics
References
9- docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050nvdPatchThird Party Advisory
- helpx.adobe.com/security/products/flash-player/apsb16-10.htmlnvdPatchVendor Advisory
- www.exploit-db.com/exploits/39779/nvdExploitThird Party AdvisoryVDB Entry
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlnvdBroken LinkThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlnvdBroken LinkThird Party Advisory
- packetstormsecurity.com/files/137050/Adobe-Flash-MovieClip.duplicateMovieClip-Use-After-Free.htmlnvdThird Party AdvisoryVDB Entry
- rhn.redhat.com/errata/RHSA-2016-0610.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/85926nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1035509nvdBroken LinkThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.