CVE-2016-1019
CRITICAL KEV RANSOMWAREAdobe Flash Player Desktop Runtime < 21.0.0.197 - Denial of Service
Title source: ruleDescription
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
References (17)
Scores
CVSS v3
9.8
EPSS
0.5801
EPSS Percentile
98.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-03-03
VulnCheck KEV
2016-04-02
InTheWild.io
2016-04-02
ENISA EUVD
EUVD-2016-2123
Ransomware Use
Confirmed
Status
published
Products (7)
adobe/air_desktop_runtime
< 21.0.0.176
adobe/air_sdk
< 21.0.0.176
adobe/air_sdk_\&_compiler
< 21.0.0.176
adobe/flash_player
< 11.2.202.577
adobe/flash_player
< 18.0.0.333
adobe/flash_player
< 21.0.0.197 (3 CPE variants)
adobe/flash_player_desktop_runtime
< 21.0.0.197
Published
Apr 07, 2016
KEV Added
Mar 03, 2022
Tracked Since
Feb 18, 2026