CVE-2016-1019

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
adobeCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
adobeflash_player_desktop_runtime
𝑥
≤ 21.0.0.197
adobeflash_player
𝑥
≤ 18.0.0.333
adobeflash_player
𝑥
≤ 21.0.0.197
adobeflash_player
𝑥
≤ 21.0.0.197
adobeflash_player
𝑥
≤ 21.0.0.197
adobeflash_player
𝑥
≤ 11.2.202.577
adobeair_desktop_runtime
𝑥
≤ 21.0.0.176
adobeair_sdk
𝑥
≤ 21.0.0.176
adobeair_sdk_\&_compiler
𝑥
≤ 21.0.0.176
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
wily
Fixed 1:20160407.1-0ubuntu0.15.10.1
released
trusty
Fixed 1:20160407.1-0ubuntu0.14.04.1
released
precise
Fixed 1:20160407.1-0ubuntu0.12.04.1
released
flashplugin-nonfree
wily
Fixed 11.2.202.616ubuntu0.15.10.1
released
trusty
Fixed 11.2.202.616ubuntu0.14.04.1
released
precise
Fixed 11.2.202.616ubuntu0.12.04.1
released
References