All CVEs View on NVD
CVE-2016-1019
CRITICAL9.8
CISA KEV
Published 2016-04-07 · Updated 2026-08-14 · Source psirt@adobe.com
Description
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known-Exploited Vulnerability
Product: Adobe — Flash Player
Name: Adobe Flash Player Arbitrary Code Execution Vulnerability
Date added: 2022-03-03 · Due: 2022-03-24
USED IN RANSOMWARE
Required action: The impacted product is end-of-life and should be disconnected if still in use.
References
- http://blogs.adobe.com/psirt/?p=1330
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2016-0610.html

