CVE-2016-1019 is a critical vulnerability in Adobe Flash Player versions 21.0.0.197 and earlier, impacting products from Adobe, Apple, Google, Linux, and Microsoft. This flaw allows remote attackers to cause a denial of service or potentially execute arbitrary code through unspecified vectors. With a CVSS score of 9.8, it presents a critical risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability compromise. The vulnerability was actively exploited in the wild in April 2016, including in known ransomware campaigns, and has garnered significant community discussion and media coverage, despite no public exploit code being available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 21.0.0.197CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.333CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
<= 21.0.0.197CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 21.0.0.197CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 21.0.0.197CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.