CVE-2016-7868 is a buffer overflow/underflow vulnerability in the RegExp class of Adobe Flash Player versions 23.0.0.207 and earlier, and 11.2.202.644 and earlier, affecting products from Adobe, Apple, Google, Linux, and Microsoft. This high-severity vulnerability (CVSS 8.8) can be exploited remotely with low complexity, requiring user interaction, and could lead to arbitrary code execution, compromising confidentiality, integrity, and availability. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), and it's not listed in CISA's KEV catalog, there has been limited community discussion and media coverage, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 11.2.202.644CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.