CVE-2016-0963 is an integer overflow vulnerability in Adobe Flash Player, AIR, AIR SDK, and AIR SDK & Compiler across Windows, OS X, and Linux platforms. This high-severity vulnerability (CVSS 8.8) allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to potential complete compromise of confidentiality, integrity, and availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability garnered significant community discussion and media coverage at the time of its disclosure, indicating notable attention. It is not listed on the CISA KEV catalog and is currently inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.0.0.306CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 20.0.0.233CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
<= 20.0.0.260CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
t-ms14jakucb-1102.5CPE matchmatch criteria | cpe:2.3:o:samsung:x14j_firmware:t-ms14jakucb-1102.5:*:*:*:*:*:*:* | ||
<= 11.2.202.569CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.