First published: Sat Mar 12 2016(Updated: )
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player | ||
All of | ||
Adobe Acrobat Reader | <=20.0.0.306 | |
Any of | ||
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
All of | ||
Adobe AIR SDK | <=20.0.0.233 | |
Android | ||
All of | ||
Any of | ||
Adobe AIR | <=20.0.0.260 | |
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
Any of | ||
iOS | ||
Apple iOS and macOS | ||
Android | ||
Microsoft Windows | ||
All of | ||
Adobe Acrobat Reader | <=11.2.202.569 | |
Linux Kernel | ||
All of | ||
Adobe Flash Player | <=20.2.2.306 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Adobe Acrobat Reader | <=20.0.0.306 | |
Microsoft Windows 10 | ||
All of | ||
Adobe Acrobat Reader | <=20.0.0.306 | |
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
All of | ||
Adobe AIR | <=20.0.0.260 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Adobe AIR SDK & Compiler | <=20.0.0.260 | |
Any of | ||
iOS | ||
Apple iOS and macOS | ||
Android | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=20.0.0.306 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe AIR SDK | <=20.0.0.233 | |
Android | ||
Adobe AIR | <=20.0.0.260 | |
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
iOS | ||
Adobe Acrobat Reader | <=11.2.202.569 | |
Adobe Flash Player | <=20.2.2.306 | |
Adobe Acrobat Reader | <=20.0.0.306 | |
Microsoft Windows 10 | ||
Adobe Acrobat Reader | <=20.0.0.306 | |
Microsoft Windows 8.1 | ||
Adobe AIR | <=20.0.0.260 | |
Adobe AIR SDK & Compiler | <=20.0.0.260 |
The impacted products are end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1010 has a critical severity level that can lead to remote code execution in affected Adobe Flash Player and AIR versions.
To fix CVE-2016-1010, update Adobe Flash Player and AIR to the latest versions, specifically versions 18.0.0.334 or 21.0.0.182 and above.
Adobe Flash Player versions prior to 18.0.0.334 for Windows, OS X, and Linux, as well as 19.x through 21.x before 21.0.0.182 are affected by CVE-2016-1010.
Yes, users can consider transitioning to HTML5 or other modern web technologies, which do not rely on Flash and are more secure.
CVE-2016-1010 affects Adobe Flash Player and AIR on Windows, macOS, Linux, and specific versions of Adobe AIR SDK.