Vulnerability Change Records for CVE-2016-1016
Change History
CVE Modified by Adobe Systems Incorporated 11/30/2016 10:3:23 PM
Action |
Type |
Old Value |
New Value |
Added |
Reference |
|
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html [No Types Assigned]
|
Added |
Reference |
|
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html [No Types Assigned]
|
Added |
Reference |
|
http://rhn.redhat.com/errata/RHSA-2016-0610.html [No Types Assigned]
|
CVE Modified by Adobe Systems Incorporated 12/02/2016 10:19:40 PM
Action |
Type |
Old Value |
New Value |
Added |
Reference |
|
http://www.securitytracker.com/id/1035509 [No Types Assigned]
|
Added |
Reference |
|
https://technet.microsoft.com/library/security/ms16-050 [No Types Assigned]
|
Modified Analysis 4/11/2016 1:57:47 PM
Action |
Type |
Old Value |
New Value |
Added |
CPE Configuration |
|
Configuration 1
AND
OR
*cpe:2.3:a:adobe:flash_player:20.0.0.306:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:19.0.0.226:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:19.0.0.245:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:20.0.0.235:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:20.0.0.228:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:20.0.0.286:*:*:*:*:*:*:*
*cpe:2.3:a:adobe:flash_player:21.0.0.97:*:*:*:*:*:*:* (and previous)
OR
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Configuration 2
AND
OR
*cpe:2.3:a:adobe:flash_player:21.0.0.97:*:*:*:*:chrome:*:* (and previous)
OR
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Configuration 3
AND
OR
cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*
OR
*cpe:2.3:a:adobe:flash_player:21.0.0.97:*:*:*:*:internet_explorer:*:* (and previous)
Configuration 4
AND
OR
*cpe:2.3:a:adobe:flash_player:18.0.0.333:*:*:*:esr:*:*:* (and previous)
OR
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
Configuration 5
AND
OR
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*
AND
*cpe:2.3:a:adobe:flash_player:21.0.0.97:*:*:*:*:internet_explorer:*:* (and previous)
*cpe:2.3:a:adobe:flash_player:21.0.0.97:*:*:*:*:edge:*:* (and previous)
Configuration 6
AND
OR
*cpe:2.3:a:adobe:flash_player:11.2.202.577:*:*:*:*:*:*:* (and previous)
OR
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
Added |
CVSS V2 |
|
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
|
Added |
CVSS V3 |
|
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
Added |
CWE |
|
NVD-CWE-Other
|
Added |
Evaluator Description |
|
<a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416: Use After Free</a>
|
Changed |
Reference Type |
https://helpx.adobe.com/security/products/flash-player/apsb16-10.html No Types Assigned
|
https://helpx.adobe.com/security/products/flash-player/apsb16-10.html Advisory, Patch
|
CVE Modified by Adobe Systems Incorporated 10/12/2018 6:11:41 PM
Action |
Type |
Old Value |
New Value |
Added |
Reference |
|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050 [No Types Assigned]
|
Removed |
Reference |
https://technet.microsoft.com/library/security/ms16-050 [No Types Assigned]
|
|
CVE Translated 4/10/2016 5:45:00 AM
Action |
Type |
Old Value |
New Value |
Added |
Translation |
|
Vulnerabilidad de uso después de liberación de memoria en la implementación del objeto Transform en Adobe Flash Player en versiones anteriores a 18.0.0.343 y 19.x hasta la versión 21.x en versiones anteriores a 21.0.0.213 en Windows y OS X y en versiones anteriores a 11.2.202.616 en Linux permite a atacantes ejecutar código arbitrario a través de una llamada de retorno flash.geom.Matrix, una vulnerabilidad diferente a CVE-2016-1011, CVE-2016-1013, CVE-2016-1017 y CVE-2016-1031.
|
Removed |
Translation |
Vulnerabilidad de uso después de liberación de memoria en la implementación del objeto Transform en Adobe Flash Player en versiones anteriores a 18.0.0.343 y 19.x hasta la versión 21.x en versiones anteriores a 21.0.0.213 en Windows y OS X y en versiones anteriores a 11.2.202.616 en Linux permite a atacantes ejecutar código arbitrario a través de un retorno de llamada flash.geom.Matrix, una vulnerabilidad diferente de CVE-2016-1011, CVE-2016-1013, CVE-2016-1017 y CVE-2016-1031.
|
|
Initial CVE Analysis 4/11/2016 1:56:47 PM
Action |
Type |
Old Value |
New Value |
CVE Modified by Adobe Systems Incorporated 2/01/2017 9:59:00 PM
Action |
Type |
Old Value |
New Value |
Added |
Reference |
|
http://www.securityfocus.com/bid/85926 [No Types Assigned]
|
|