CVE-2016-1019

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
adobeflash_player_desktop_runtime
𝑥
≤ 21.0.0.197
adobeflash_player_esr
𝑥
≤ 18.0.0.333
adobeflash_player
𝑥
≤ 21.0.0.197
adobeflash_player
𝑥
≤ 21.0.0.197
adobeflash_player
𝑥
≤ 21.0.0.197
adobeflash_player
𝑥
≤ 11.2.202.577
adobeair_desktop_runtime
𝑥
≤ 21.0.0.176
adobeair_sdk
𝑥
≤ 21.0.0.176
adobeair_sdk_\&_compiler
𝑥
≤ 21.0.0.176
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
precise
Fixed 1:20160407.1-0ubuntu0.12.04.1
released
trusty
Fixed 1:20160407.1-0ubuntu0.14.04.1
released
wily
Fixed 1:20160407.1-0ubuntu0.15.10.1
released
flashplugin-nonfree
precise
Fixed 11.2.202.616ubuntu0.12.04.1
released
trusty
Fixed 11.2.202.616ubuntu0.14.04.1
released
wily
Fixed 11.2.202.616ubuntu0.15.10.1
released
References