---
title: "CVE-2016-1109\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-1109?format=md
keywords: index, follow
---

# CVE-2016-1109

Publication date 11 May 2016

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2016-1109?format=md#impact-score)

Toggle side navigation

## Description

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as
used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11
and Microsoft Edge, has unknown impact and attack vectors, a different
vulnerability than other CVEs listed in MS16-064.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2016-1109?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| adobe-flashplugin | 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| flashplugin-nonfree | 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

probably microsoft-specific version

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1109)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-1109)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-1109)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-1109)

### Other references

* <http://technet.microsoft.com/security/bulletin/MS16-064>
* <https://www.cve.org/CVERecord?id=CVE-2016-1109>
