Cyber Resilience

CVE-2016-1019

Adobe Flash Player ≤ 18.0.0.333

CISA KEVActive ExploitationEUVD ExploitedRansomware-linked
Published
07 April 2016
Modified
21 April 2026
KEV Added
03 March 2022
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.22 97th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2016-1019 is a critical-severity an unspecified weakness vulnerability in Apple Mac Os X. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 3% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Adobe Flash Player versions 21.0.0.197 and earlier contain an unspecified vulnerability that can be triggered to produce an application crash or potentially allow arbitrary code execution. The flaw carries a CVSS 3.1 base score of 9.8 and is tracked under NVD-CWE-noinfo, indicating insufficient public detail on the underlying weakness.

Remote attackers can exploit the issue over the network without authentication or user interaction, enabling denial-of-service conditions or full code execution on affected systems. The vulnerability was observed being exploited in the wild during April 2016.

Adobe security advisories and corresponding updates from Linux distributions such as openSUSE document the availability of patched Flash Player releases and recommend prompt installation to address the exposure. The in-the-wild exploitation noted at disclosure time underscores the need for rapid remediation in environments still running legacy Flash components.

EU & UK References

Vulnerability Data

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CWE(s)
KEV Date Added
03 March 2022

Related Threats

CVEs Like This One

CVE-2016-0984Same product: Adobe Air Desktop Runtimeboth on KEV
CVE-2016-1010Same product: Adobe Air Desktop Runtimeboth on KEV
CVE-2016-7892Same product: Adobe Flash Playerboth on KEV
CVE-2017-11292Same product: Adobe Flash Playerboth on KEV
CVE-2018-5002Same product: Adobe Flash Playerboth on KEV
CVE-2018-15982Same product: Adobe Flash Playerboth on KEV
CVE-2016-7855Same product: Adobe Flash Playerboth on KEV
CVE-2014-8439Same product: Adobe Air Sdkboth on KEV
CVE-2012-0767Same product: Adobe Flash Playerboth on KEV
CVE-2012-0754Same product: Adobe Flash Playerboth on KEV

Affected Assets

adobe
flash player desktop runtime
≤ 21.0.0.197
adobe
flash player
≤ 18.0.0.333 · ≤ 21.0.0.197 · ≤ 21.0.0.197
adobe
air desktop runtime
≤ 21.0.0.176
adobe
air sdk
≤ 21.0.0.176
adobe
air sdk \& compiler
≤ 21.0.0.176

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References