Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information from process memory via unspecified vectors.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00017.html | broken link third party advisory vendor advisory |
https://security.gentoo.org/glsa/201607-03 | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00016.html | broken link third party advisory vendor advisory |
https://helpx.adobe.com/security/products/flash-player/apsb16-25.html | patch vendor advisory |
https://access.redhat.com/errata/RHSA-2016:1423 | third party advisory vendor advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-093 | third party advisory patch vendor advisory |
https://www.exploit-db.com/exploits/40355/ | exploit vdb entry third party advisory |
http://www.securityfocus.com/bid/91724 | vdb entry third party advisory broken link |
http://www.securitytracker.com/id/1036280 | vdb entry third party advisory broken link |