CVE-2016-0984 is a critical use-after-free vulnerability in Adobe Flash Player, AIR, and AIR SDK across Windows, OS X, and Linux platforms. This flaw allows remote attackers to execute arbitrary code on affected systems. With a CVSS score of 8.8 (High), it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability has been actively exploited in the wild, as confirmed by its presence in the CISA KEV catalog and mentions of its use by the BlackOasis APT group, with public exploit code available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.0.0.272CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 20.0.0.272CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 11.2.202.559CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 20.0.0.286CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.326CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.