<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for flash-player</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:1625-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-06-18T20:48:48Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-06-18T20:48:48Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-06-18T20:48:48Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for flash-player</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
Adobe flash-player was updated to 11.2.202.626 to fix the following security issues:

Security update to 11.2.202.626 (boo#984695):
* APSB16-18, CVE-2016-4122, CVE-2016-4123, CVE-2016-4124,
  CVE-2016-4125, CVE-2016-4127, CVE-2016-4128, CVE-2016-4129,
  CVE-2016-4130, CVE-2016-4131, CVE-2016-4132, CVE-2016-4133,
  CVE-2016-4134, CVE-2016-4135, CVE-2016-4136, CVE-2016-4137,
  CVE-2016-4138, CVE-2016-4139, CVE-2016-4140, CVE-2016-4141,
  CVE-2016-4142, CVE-2016-4143, CVE-2016-4144, CVE-2016-4145,
  CVE-2016-4146, CVE-2016-4147, CVE-2016-4148, CVE-2016-4149,
  CVE-2016-4150, CVE-2016-4151, CVE-2016-4152, CVE-2016-4153,
  CVE-2016-4154, CVE-2016-4155, CVE-2016-4156, CVE-2016-4166,
  CVE-2016-4171

Please see https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
for more information.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      <Description>E-Mail link for openSUSE-SU-2016:1625-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE 13.1 NonFree">
      <Branch Type="Product Name" Name="openSUSE 13.1 NonFree">
        <FullProductName ProductID="openSUSE 13.1 NonFree">openSUSE 13.1 NonFree</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="flash-player-11.2.202.626-165.1">
      <FullProductName ProductID="flash-player-11.2.202.626-165.1">flash-player-11.2.202.626-165.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="flash-player-gnome-11.2.202.626-165.1">
      <FullProductName ProductID="flash-player-gnome-11.2.202.626-165.1">flash-player-gnome-11.2.202.626-165.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="flash-player-kde4-11.2.202.626-165.1">
      <FullProductName ProductID="flash-player-kde4-11.2.202.626-165.1">flash-player-kde4-11.2.202.626-165.1</FullProductName>
    </Branch>
    <Relationship ProductReference="flash-player-11.2.202.626-165.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.1 NonFree">
      <FullProductName ProductID="openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1">flash-player-11.2.202.626-165.1 as a component of openSUSE 13.1 NonFree</FullProductName>
    </Relationship>
    <Relationship ProductReference="flash-player-gnome-11.2.202.626-165.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.1 NonFree">
      <FullProductName ProductID="openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1">flash-player-gnome-11.2.202.626-165.1 as a component of openSUSE 13.1 NonFree</FullProductName>
    </Relationship>
    <Relationship ProductReference="flash-player-kde4-11.2.202.626-165.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.1 NonFree">
      <FullProductName ProductID="openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1">flash-player-kde4-11.2.202.626-165.1 as a component of openSUSE 13.1 NonFree</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4122</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4122.html</URL>
        <Description>CVE-2016-4122</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4123</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4123.html</URL>
        <Description>CVE-2016-4123</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4124</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4124.html</URL>
        <Description>CVE-2016-4124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4125</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4125.html</URL>
        <Description>CVE-2016-4125</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4127</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4127.html</URL>
        <Description>CVE-2016-4127</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4128</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4128.html</URL>
        <Description>CVE-2016-4128</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4129</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4129.html</URL>
        <Description>CVE-2016-4129</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4130</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4130.html</URL>
        <Description>CVE-2016-4130</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4131</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4131.html</URL>
        <Description>CVE-2016-4131</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4132</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4132.html</URL>
        <Description>CVE-2016-4132</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4133</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4133.html</URL>
        <Description>CVE-2016-4133</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4134</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4134.html</URL>
        <Description>CVE-2016-4134</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4135</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4135.html</URL>
        <Description>CVE-2016-4135</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4136</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4136.html</URL>
        <Description>CVE-2016-4136</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4137</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4137.html</URL>
        <Description>CVE-2016-4137</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4138</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4138.html</URL>
        <Description>CVE-2016-4138</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4139</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4139.html</URL>
        <Description>CVE-2016-4139</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4140</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4140.html</URL>
        <Description>CVE-2016-4140</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4141</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4141.html</URL>
        <Description>CVE-2016-4141</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4142</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4142.html</URL>
        <Description>CVE-2016-4142</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4143</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4143.html</URL>
        <Description>CVE-2016-4143</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4144</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4144.html</URL>
        <Description>CVE-2016-4144</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4145</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4145.html</URL>
        <Description>CVE-2016-4145</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4146</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4146.html</URL>
        <Description>CVE-2016-4146</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4147</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4147.html</URL>
        <Description>CVE-2016-4147</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4148</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4148.html</URL>
        <Description>CVE-2016-4148</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4149</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4149.html</URL>
        <Description>CVE-2016-4149</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4150</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4150.html</URL>
        <Description>CVE-2016-4150</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="29">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4151</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4151.html</URL>
        <Description>CVE-2016-4151</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="30">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4152</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4152.html</URL>
        <Description>CVE-2016-4152</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="31">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4153</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4153.html</URL>
        <Description>CVE-2016-4153</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="32">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4154</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4154.html</URL>
        <Description>CVE-2016-4154</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="33">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4155</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4155.html</URL>
        <Description>CVE-2016-4155</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="34">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4156</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4156.html</URL>
        <Description>CVE-2016-4156</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="35">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.</Note>
    </Notes>
    <CVE>CVE-2016-4166</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4166.html</URL>
        <Description>CVE-2016-4166</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="36">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.</Note>
    </Notes>
    <CVE>CVE-2016-4171</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.1 NonFree:flash-player-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-gnome-11.2.202.626-165.1</ProductID>
        <ProductID>openSUSE 13.1 NonFree:flash-player-kde4-11.2.202.626-165.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4171.html</URL>
        <Description>CVE-2016-4171</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/984695</URL>
        <Description>SUSE Bug 984695</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
