peter bassill · operator
$ cve CVE-2016-4138 JSON

CVE-2016-4138 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 25.4% (pctl 98)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS25.42% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2016-06-16
Last modified2026-06-17

Affected (16)

VendorProduct
adobeflash player
adobeflash player desktop runtime
applemacos
googlechrome os
linuxlinux kernel
microsoftwindows
microsoftwindows 10
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 2012
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise workstation extension

Public exploits

SourceTitleDate
exploit-dbAdobe Flash - ATF Image Packing Overflow2016-07-11

References

→ the Explorer  ·  watch your stack  ·  NVD