CVE-2016-6987 is a critical use-after-free vulnerability in Adobe Flash Player affecting versions before 18.0.0.382, 19.x through 23.x before 23.0.0.185 on Windows and OS X, and before 11.2.202.637 on Linux. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating that it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community discussion and media coverage, including an article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 18.0.0.375CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.