CVE-2016-0984: Adobe Flash Player and AIR Use-After-Free Vulnerability

Published Feb 10, 2016
·
Updated

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.

Other sources

Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

CISA

Affected Software

42 affected components
Adobe Flash Player and AIR
Adobe Flash Player<=11.2.202.559
Linux Linux kernel
Adobe Flash Player Desktop Runtime<=20.0.0.286
Apple iOS and macOS
Microsoft Windows
Adobe Flash Player<=18.0.0.326
Microsoft Windows 10
Microsoft Windows 8.1
Adobe Flash Player Internet Explorer<=20.0.0.272
Adobe Flash Player Chrome<=20.0.0.286
Google Chrome OS
Adobe Flash Player Edge<=20.0.0.272
Adobe Air Desktop Runtime<=20.0.0.233
Adobe AIR SDK<=20.0.0.233
Apple iPhone OS
Google Android
Adobe Air Sdk \& Compiler<=20.0.0.233
All of the following
Adobe Flash Player Internet Explorer<=20.0.0.272
Microsoft Windows
All of the following
Adobe Flash Player Edge<=20.0.0.272
Microsoft Windows
All of the following
Adobe Flash Player<=11.2.202.559
Linux Linux kernel
All of the following
Adobe Flash Player Desktop Runtime<=20.0.0.286
Microsoft Windows
All of the following
Adobe Flash Player<=18.0.0.326
Microsoft Windows
All of the following
Adobe Flash Player Chrome<=20.0.0.286
Any of the following
Google Chrome OS
Linux Linux kernel
Microsoft Windows
All of the following
Adobe Air Desktop Runtime<=20.0.0.233
Microsoft Windows
All of the following
Adobe AIR SDK<=20.0.0.233
Any of the following
Apple iPhone OS
Google Android
Microsoft Windows
All of the following
Adobe Air Sdk \& Compiler<=20.0.0.233
Any of the following
Apple iPhone OS
Google Android
Microsoft Windows

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Adobe Flash Player to a version that resolves this vulnerability.

    Fixed in 18.0.0.329
  2. Upgrade

    Upgrade Adobe Flash Player 19.x to a version that resolves this vulnerability.

    Fixed in 19.x
  3. Upgrade

    Upgrade Adobe Flash Player 20.x to a version that resolves this vulnerability.

    Fixed in 20.0.0.306
  4. Upgrade

    Upgrade Adobe Flash Player Linux to a version that resolves this vulnerability.

    Fixed in 11.2.202.569
  5. Upgrade

    Upgrade Adobe AIR to a version that resolves this vulnerability.

    Fixed in 20.0.0.260
  6. Upgrade

    Upgrade Adobe AIR SDK to a version that resolves this vulnerability.

    Fixed in 20.0.0.260
  7. Upgrade

    Upgrade Adobe AIR SDK & Compiler to a version that resolves this vulnerability.

    Fixed in 20.0.0.260
  8. Compensating control

    Disconnect Adobe Flash Player and Adobe AIR from networks if they are still in use, since the impacted products are end-of-life.

Event History

Feb 10, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 25, 2022
Known Exploited
via CISA·12:00 AM
Mar 1, 58274
Event
05:26 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-0984?

CVE-2016-0984 is rated as critical due to the potential for remote code execution if exploited.

2

How do I fix CVE-2016-0984?

To fix CVE-2016-0984, update Adobe Flash Player and AIR to the latest version that is not affected by this vulnerability.

3

Which versions of Adobe products are affected by CVE-2016-0984?

Adobe Flash Player versions before 18.0.0.329 and Adobe AIR versions before 20.0.0.260 are affected by CVE-2016-0984.

4

What types of attacks can exploit CVE-2016-0984?

CVE-2016-0984 can be exploited through specially crafted content that could allow an attacker to execute arbitrary code.

5

Are current operating systems vulnerable to CVE-2016-0984?

CVE-2016-0984 affects multiple operating systems including Windows and OS X, depending on the version of Adobe Flash Player or AIR installed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203