CVE-2016-1019
Adobe Flash Player Arbitrary Code Execution Vulnerability
CVSS
9.8
Critical
EPSS
22.5%
p98
KEV
YES
Mar 3, 2022
Exploit Today
79
0-100
Published: Apr 7, 2016 · Last modified: Aug 14, 2026
Product
Adobe / Flash Player
Vulnerability
Adobe Flash Player Arbitrary Code Execution Vulnerability
Added to KEV
Mar 3, 2022
Remediate by
Mar 24, 2022
Known ransomware use
Yes
Summary description
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2016-1019
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
- blogs.adobe.comhttp://blogs.adobe.com/psirt/?p=1330
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html
- rhn.redhat.comhttp://rhn.redhat.com/errata/RHSA-2016-0610.html
- www.securityfocus.comhttp://www.securityfocus.com/bid/85856
- www.securitytracker.comhttp://www.securitytracker.com/id/1035491
- docs.microsoft.comhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050
- helpx.adobe.comhttps://helpx.adobe.com/security/products/flash-player/apsa16-01.html
- helpx.adobe.comhttps://helpx.adobe.com/security/products/flash-player/apsb16-10.html
- security.gentoo.orghttps://security.gentoo.org/glsa/201606-08
- www.fireeye.comhttps://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.html
- blogs.adobe.comhttp://blogs.adobe.com/psirt/?p=1330
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html