CVE-2016-6931 is a critical use-after-free vulnerability affecting Adobe Flash Player across Windows, OS X, and Linux platforms, specifically versions before 18.0.0.375, 19.x through 23.x before 23.0.0.162, and before 11.2.202.635 respectively. This flaw, rated 8.8 HIGH on CVSS, allows unauthenticated attackers to achieve arbitrary code execution through unspecified vectors, typically requiring user interaction. While no public exploit code or active exploitation has been confirmed, its high severity and potential for complete compromise of confidentiality, integrity, and availability warrant immediate patching. Community discussion and media coverage are limited, suggesting it was not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.632CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.366CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.