CVE-2016-1019

CRITICAL KEV RANSOMWARE

Adobe Flash Player Desktop Runtime < 21.0.0.197 - Denial of Service

Title source: rule

Description

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

References (17)

Scores

CVSS v3 9.8
EPSS 0.5801
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-03
VulnCheck KEV 2016-04-02
InTheWild.io 2016-04-02
ENISA EUVD EUVD-2016-2123
Ransomware Use Confirmed
Status published
Products (7)
adobe/air_desktop_runtime < 21.0.0.176
adobe/air_sdk < 21.0.0.176
adobe/air_sdk_\&_compiler < 21.0.0.176
adobe/flash_player < 11.2.202.577
adobe/flash_player < 18.0.0.333
adobe/flash_player < 21.0.0.197 (3 CPE variants)
adobe/flash_player_desktop_runtime < 21.0.0.197
Published Apr 07, 2016
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026