CVE-2016-1101
Estado: ModificadaAlta (7.5)—💥 Exploit
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 38%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Adobe Flash - Heap Overflow in ATF Processing Image Reading (17/5/2016)
Tecnologías afectadas (3)
CWE
- NVD-CWE-noinfo
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
- http://packetstormsecurity.com/files/137052/Adobe-Flash-ATF-Processing-Heap-Overflow.html
- http://rhn.redhat.com/errata/RHSA-2016-1079.html
- http://www.securitytracker.com/id/1035827
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-064
- https://helpx.adobe.com/security/products/flash-player/apsb16-15.html
- https://www.exploit-db.com/exploits/39827/
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
- http://packetstormsecurity.com/files/137052/Adobe-Flash-ATF-Processing-Heap-Overflow.html
- http://rhn.redhat.com/errata/RHSA-2016-1079.html
- http://www.securitytracker.com/id/1035827
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-064
- https://helpx.adobe.com/security/products/flash-player/apsb16-15.html
- https://www.exploit-db.com/exploits/39827/
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-1101",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-05-11T11:00:12.280",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html",
"source": "psirt@adobe.com"
},
{
"url": "http://packetstormsecurity.com/files/137052/Adobe-Flash-ATF-Processing-Heap-Overflow.html",
"source": "psirt@adobe.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-1079.html",
"source": "psirt@adobe.com"
},
{
"url": "http://www.securitytracker.com/id/1035827",
"source": "psirt@adobe.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-064",
"source": "psirt@adobe.com"
},
{
"url": "https://helpx.adobe.com/security/products/flash-player/apsb16-15.html",
"source": "psirt@adobe.com"
},
{
"url": "https://www.exploit-db.com/exploits/39827/",
"source": "psirt@adobe.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/137052/Adobe-Flash-ATF-Processing-Heap-Overflow.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-1079.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1035827",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-064",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://helpx.adobe.com/security/products/flash-player/apsb16-15.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/39827/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064."
},
{
"lang": "es",
"value": "Vulnerabilidad no especificada en Adobe Flash Player 21.0.0.213 y versiones anteriores, según se utiliza en las librerías Adobe Flash en Microsoft Internet Explorer 10 y 11 y Microsoft Edge, tiene impacto y vectores de ataque desconocidos, una vulnerabilidad diferente a otras CVEs listadas en MS16-064."
}
],
"lastModified": "2026-06-17T00:41:17.790",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDFF3E0F-29D6-40DA-B5F5-42AC82B52EF1",
"versionEndIncluding": "21.0.0.213"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77D197D7-57FB-4898-8C70-B19D5F0D5BE0"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5808661-A082-4CBE-808C-B253972487B4"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7809F78-8D56-4925-A8F9-4119B973A667"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}