CVE-2016-1000

Published: 12 March 2016

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
adobe-flashplugin
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 16.04 ESM (Xenial Xerus)
Released (1:20160310.1-0ubuntu1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was released [1:20160310.1-0ubuntu0.14.04.1])
flashplugin-nonfree
Launchpad, Ubuntu, Debian
Upstream
Released (11.2.202.577)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (11.2.202.577ubuntu1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was released [11.2.202.577ubuntu0.14.04.1])