Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies. Successful exploitation could lead to arbitrary code execution.
2016-12-15T06:59:34.297
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | flash_player_desktop_runtime | ≤ 23.0.0.207 | Yes |
Operating System | apple | mac_os_x | - | No |
Operating System | microsoft | windows | - | No |
Application | adobe | flash_player | ≤ 23.0.0.207 | Yes |
Application | adobe | flash_player | ≤ 23.0.0.207 | Yes |
Operating System | microsoft | windows_10 | - | No |
Operating System | microsoft | windows_8.1 | - | No |
Application | adobe | flash_player | ≤ 23.0.0.207 | Yes |
Operating System | apple | mac_os_x | - | No |
Operating System | chrome_os | - | No | |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |
Application | adobe | flash_player | ≤ 11.2.202.644 | Yes |
Operating System | linux | linux_kernel | - | No |