CVE-2016-7870 is a high-severity buffer overflow/underflow vulnerability in Adobe Flash Player versions 23.0.0.207 and earlier, and 11.2.202.644 and earlier, specifically within the RegExp class for certain search strategies. This flaw impacts products from Adobe, Apple, Google, Linux, and Microsoft. With a CVSS score of 8.8 (HIGH), successful exploitation could lead to arbitrary code execution, requiring user interaction (UI:R) but with low attack complexity (AC:L) over a network (AV:N). While the vulnerability has a high potential impact on confidentiality, integrity, and availability (C:H/I:H/A:H), there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond a single article announcing Adobe updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 11.2.202.644CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.