Back

CRITICAL KEV Used in ransomware campaigns

flash-plugin: multiple code execution issues fixed in APSB16-10

Published Apr 7, 2016 ·Due Mar 24, 2022

Description

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (22)

Change history (3)
  1. CISA ADP
    • SSVC automatable changed from yes to no
  2. CISA ADP
    • SSVC automatable changed from no to yes
  3. CISA ADP
    • SSVC automatable changed from yes to no
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Apr 7, 2016
Updated Oct 1, 2026
Reserved Dec 22, 2015
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Analyzed
Modified Aug 14, 2026
Red Hat
Severity Critical
Public date Apr 7, 2016