Description
Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via a URLLoader.load call, a different vulnerability than CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
Published: 2016-02-10
Score: 8.8 High
EPSS: 5.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-0983 Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via a URLLoader.load call, a different vulnerability than CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
History

No history.

Subscriptions

Adobe Air Desktop Runtime Air Sdk Air Sdk \& Compiler Flash Player Flash Player Desktop Runtime
Apple Iphone Os Mac Os X
Google Android Chrome Os
Linux Linux Kernel
Microsoft Windows Windows 10 Windows 8.1
Redhat Rhel Extras
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-08-05T22:38:41.213Z

Reserved: 2015-12-22T00:00:00.000Z

Link: CVE-2016-0973

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-02-10T20:59:21.063

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-0973

cve-icon Redhat

Severity : Critical

Publid Date: 2016-02-09T00:00:00Z

Links: CVE-2016-0973 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses