ALT-BU-2016-2646-1
Branch t6 update bulletin.
Closed vulnerabilities
BDU:2016-00819
Уязвимости средства криптографической защиты OpenSSH, позволяющие нарушителю обойти ограничения интерпретатора команд
Modified: 2025-04-12
CVE-2016-3115
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c.diff?r1=1.281&r2=1.282&f=h
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183101.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183122.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178838.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179924.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180491.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184264.html
- http://packetstormsecurity.com/files/136234/OpenSSH-7.2p1-xauth-Command-Injection-Bypass.html
- http://rhn.redhat.com/errata/RHSA-2016-0465.html
- http://rhn.redhat.com/errata/RHSA-2016-0466.html
- http://seclists.org/fulldisclosure/2016/Mar/46
- http://seclists.org/fulldisclosure/2016/Mar/47
- http://www.openssh.com/txt/x11fwd.adv
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/84314
- http://www.securitytracker.com/id/1035249
- https://bto.bluecoat.com/security-advisory/sa121
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-3115
- https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html
- https://security.gentoo.org/glsa/201612-18
- https://www.exploit-db.com/exploits/39569/
- https://www.freebsd.org/security/advisories/FreeBSD-SA-16:14.openssh.asc
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c.diff?r1=1.281&r2=1.282&f=h
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183101.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183122.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178838.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179924.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180491.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184264.html
- http://packetstormsecurity.com/files/136234/OpenSSH-7.2p1-xauth-Command-Injection-Bypass.html
- http://rhn.redhat.com/errata/RHSA-2016-0465.html
- http://rhn.redhat.com/errata/RHSA-2016-0466.html
- http://seclists.org/fulldisclosure/2016/Mar/46
- http://seclists.org/fulldisclosure/2016/Mar/47
- http://www.openssh.com/txt/x11fwd.adv
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/84314
- http://www.securitytracker.com/id/1035249
- https://bto.bluecoat.com/security-advisory/sa121
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-3115
- https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html
- https://security.gentoo.org/glsa/201612-18
- https://www.exploit-db.com/exploits/39569/
- https://www.freebsd.org/security/advisories/FreeBSD-SA-16:14.openssh.asc
Package adobe-flash-player updated to version 11-alt60 for branch t6 in task 161443.
Closed vulnerabilities
BDU:2016-00778
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00782
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00783
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00784
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00785
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00786
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00787
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00788
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00789
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00790
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00791
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00792
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00793
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00794
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00795
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00796
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00797
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00798
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00799
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00800
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код
BDU:2016-00801
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00802
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00803
Уязвимость программных платформ Flash Player, Flash Player ESR и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2025-04-12
CVE-2016-0960
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, CVE-2016-1002, and CVE-2016-1005.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0961
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0960, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, CVE-2016-1002, and CVE-2016-1005.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0962
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, CVE-2016-1002, and CVE-2016-1005.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0963
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0993 and CVE-2016-1010.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84308
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84308
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0986
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0989, CVE-2016-0992, CVE-2016-1002, and CVE-2016-1005.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0987
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0988
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0989
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0992, CVE-2016-1002, and CVE-2016-1005.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0990
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0991
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0992
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-1002, and CVE-2016-1005.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0993
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-1010.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84308
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84308
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0994
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code by using the actionCallMethod opcode with crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- http://www.zerodayinitiative.com/advisories/ZDI-16-194/
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- http://www.zerodayinitiative.com/advisories/ZDI-16-194/
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0995
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0996
Use-after-free vulnerability in the setInterval method in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via crafted arguments, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- http://www.zerodayinitiative.com/advisories/ZDI-16-193/
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- http://www.zerodayinitiative.com/advisories/ZDI-16-193/
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0997
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39613/
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39613/
Modified: 2025-04-12
CVE-2016-0998
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39612/
- https://www.exploit-db.com/exploits/39631/
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39612/
- https://www.exploit-db.com/exploits/39631/
Modified: 2025-04-12
CVE-2016-0999
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-1000.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39611/
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39611/
Modified: 2025-04-12
CVE-2016-1000
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, and CVE-2016-0999.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://rhn.redhat.com/errata/RHSA-2016-1582.html
- http://rhn.redhat.com/errata/RHSA-2016-1583.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39610/
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://rhn.redhat.com/errata/RHSA-2016-1582.html
- http://rhn.redhat.com/errata/RHSA-2016-1583.html
- http://www.securityfocus.com/bid/84312
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39610/
Modified: 2025-04-12
CVE-2016-1001
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39609/
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39609/
Modified: 2025-04-12
CVE-2016-1002
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, and CVE-2016-1005.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39608/
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39608/
Modified: 2025-04-12
CVE-2016-1005
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allow attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and memory corruption) via crafted MPEG-4 data, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, and CVE-2016-1002.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- http://www.zerodayinitiative.com/advisories/ZDI-16-192/
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84311
- http://www.securitytracker.com/id/1035251
- http://www.zerodayinitiative.com/advisories/ZDI-16-192/
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-1010
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84308
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html
- http://www.securityfocus.com/bid/84308
- http://www.securitytracker.com/id/1035251
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.html
- https://security.gentoo.org/glsa/201603-07