Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
via cve_org
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 10.0 | 10.0 | 10.0 |
| 3.1 | Primary | NVD | 9.8 | 3.9 | 5.9 |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Secondary | NVD | 7.8 | 1.8 | 5.9 |
| 3.1 | Secondary | ENISA EUVD | 7.8 | — | — |