CVE-2016-4117

Publication date 11 May 2016

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

Status

Package Ubuntu Release Status
adobe-flashplugin 16.04 LTS xenial
Fixed 1:20160512.1-0ubuntu0.16.04.1
15.10 wily
Fixed 1:20160512.1-0ubuntu0.15.10.1
14.04 LTS trusty
Fixed 1:20160512.1-0ubuntu0.14.04.1
12.04 LTS precise
Fixed 1:20160512.1-0ubuntu0.12.04.1
flashplugin-nonfree 16.04 LTS xenial
Fixed 11.2.202.621ubuntu0.16.04.1
15.10 wily
Fixed 11.2.202.621ubuntu0.15.10.1
14.04 LTS trusty
Fixed 11.2.202.621ubuntu0.14.04.1
12.04 LTS precise
Fixed 11.2.202.621ubuntu0.12.04.1

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities