CVE-2016-4247 is a race condition vulnerability in Adobe Flash Player, affecting versions before 18.0.0.366 and 22.0.0.209 on Windows and OS X, and before 11.2.202.632 on Linux. This medium-severity vulnerability (CVSS 5.3) requires high attack complexity and user interaction, allowing attackers to obtain sensitive information. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating its relevance despite its inactive status on the CISA Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.360CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.