CVE-2016-1019
Executive Summary
Adobe Flash Player 21.0.0.197 and earlier are vulnerable to remote exploitation, allowing attackers to crash the application or potentially execute arbitrary code via unspecified vectors. The flaw was actively exploited in the wild in April 2016 and is listed as a KEV by CISA.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2016-04-07T10:59:01.447 - Last Modified: 2026-10-01T20:17:16.080
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-03-03)
Original Description: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
"They must often change, who would be constant in happiness or wisdom."
— Confucius