Back
CVE-2016-4138
CRITICAL
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published: Jun 16, 2016
Modified: Jun 17, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (19)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| adobe | flash_player | * |
| adobe | flash_player_desktop_runtime | * |
| adobe | flash_player | * |
| adobe | flash_player | * |
| adobe | flash_player | * |
| adobe | flash_player | * |
| opensuse | opensuse | 13.1 |
| opensuse | opensuse | 13.2 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_workstation_extension | 12 |
| suse | linux_enterprise_workstation_extension | 12 |
| adobe | flash_player | - |
GitHub Security Advisory GHSA-p3r5-wjf8-mjhr
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe...
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html Broken Link, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html Broken Link, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html Broken Link, Third Party Advisory
- http://www.securitytracker.com/id/1036117 Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1238 Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083 Patch, Third Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.html Vendor Advisory
- https://www.exploit-db.com/exploits/40090/ Exploit, Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html Broken Link, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html Broken Link, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html Broken Link, Third Party Advisory
- http://www.securitytracker.com/id/1036117 Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1238 Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083 Patch, Third Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.html Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
25.42%
Top 2% most likely to be exploited
Threat Score
46.8 / 100
Data Sources
NVD
EPSS
GitHub