CVE-2016-1106 is an unspecified vulnerability affecting Adobe Flash Player versions 21.0.0.213 and earlier, specifically when used within Microsoft Internet Explorer 10, 11, and Microsoft Edge. This high-severity vulnerability (CVSS 7.5) has unknown impact and attack vectors, though one exploit (SetNative Use-After-Free) has been publicly disclosed. While not in the KEV catalog, its high FAUCET Risk Score of 98/100 and EPSS score indicate a significant threat. Despite the availability of exploit code, there is no evidence of active exploitation or widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* | ||
<= 21.0.0.213CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.