CVE-2016-0971
HIGHAdobe Flash Player <18.0.0.329,19.x,20.x - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-0971. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a heap overflow vulnerability in the URLStream class due to improper ATF processing, leading to a crash. The PoC is provided as a binary file (39465.zip) that triggers the issue.
Description
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors.
Exploits (1)
This exploit demonstrates a heap overflow vulnerability in the URLStream class due to improper ATF processing, leading to a crash. The PoC is provided as a binary file (39465.zip) that triggers the issue.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H