flash-plugin: multiple code execution issues fixed in APSB16-10
Published Apr 7, 2016 ·Due Mar 24, 2022
9.8
CRITICALCVSS 3.1
EPSS 22.32%
Description
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Affected products
No data.
Configuration 1
Configuration 2
Configuration 3
- ≤ 21.0.0.197
Configuration 4
- ≤ 21.0.0.197
Running on/with
- n/a
Configuration 5
- ≤ 21.0.0.197
Running on/with
- n/a
- n/a
Configuration 6
- ≤ 11.2.202.577
Running on/with
- n/a
Configuration 7
Configuration 8
No data.
Red Hat Enterprise Linux 5 Supplementary
flash-plugin-0:11.2.202.616-1.el5
Fixed · RHSA-2016:0610
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:11.2.202.616-1.el6_7
Fixed · RHSA-2016:0610
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | flash-plugin-0:11.2.202.616-1.el5 | Fixed | RHSA-2016:0610 |
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:11.2.202.616-1.el6_7 | Fixed | RHSA-2016:0610 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CISA ADP) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Mar 3, 2022
Patch Due
Mar 24, 2022
Required Action
The impacted product is end-of-life and should be disconnected if still in use.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (35 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 22.32% (0.22316) | 97.62th | v5 (v2026.06.15) |
| Jun 15, 2026 | 22.49% (0.22487) | 97.40th | v5 (v2026.06.15) |
| Jun 13, 2026 | 53.49% (0.53493) | 98.05th | v4 (v2025.03.14) |
| May 22, 2026 | 56.70% (0.56698) | 98.16th | v4 (v2025.03.14) |
| Apr 22, 2026 | 58.01% (0.58008) | 98.19th | v4 (v2025.03.14) |
| Jan 31, 2026 | 72.38% (0.72382) | 98.72th | v4 (v2025.03.14) |
| Jan 25, 2026 | 74.46% (0.74460) | 98.80th | v4 (v2025.03.14) |
| Jan 20, 2026 | 70.29% (0.70287) | 98.63th | v4 (v2025.03.14) |
| Nov 18, 2025 | 74.46% (0.74460) | 98.91th | v4 (v2025.03.14) |
| Nov 14, 2025 | 83.45% (0.83453) | 99.23th | v4 (v2025.03.14) |
| Nov 12, 2025 | 80.83% (0.80828) | 99.09th | v4 (v2025.03.14) |
| Nov 1, 2025 | 82.23% (0.82227) | 99.18th | v4 (v2025.03.14) |
| Oct 22, 2025 | 80.83% (0.80828) | 99.09th | v4 (v2025.03.14) |
| Oct 18, 2025 | 78.43% (0.78426) | 98.98th | v4 (v2025.03.14) |
| Sep 23, 2025 | 76.28% (0.76278) | 98.89th | v4 (v2025.03.14) |
| Sep 10, 2025 | 78.09% (0.78093) | 98.98th | v4 (v2025.03.14) |
| Jul 13, 2025 | 79.39% (0.79388) | 99.02th | v4 (v2025.03.14) |
| Mar 30, 2025 | 81.48% (0.81479) | 99.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 83.56% (0.83564) | 99.10th | v4 (v2025.03.14) |
| Mar 17, 2025 | 81.48% (0.81479) | 99.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 95.32% (0.95317) | 99.44th | v3 (v2023.03.01) |
| Jun 5, 2024 | 95.32% (0.95317) | 99.35th | v3 (v2023.03.01) |
| May 7, 2024 | 95.64% (0.95643) | 99.40th | v3 (v2023.03.01) |
| Apr 2, 2024 | 95.61% (0.95614) | 99.36th | v3 (v2023.03.01) |
| Mar 1, 2024 | 95.43% (0.95429) | 99.31th | v3 (v2023.03.01) |
| Dec 27, 2023 | 95.18% (0.95177) | 99.16th | v3 (v2023.03.01) |
| Nov 24, 2023 | 95.61% (0.95608) | 99.23th | v3 (v2023.03.01) |
| Oct 10, 2023 | 95.41% (0.95406) | 99.13th | v3 (v2023.03.01) |
| Oct 9, 2023 | 94.37% (0.94374) | 98.93th | v3 (v2023.03.01) |
| Jul 9, 2023 | 95.41% (0.95406) | 99.05th | v3 (v2023.03.01) |
| Mar 11, 2023 | 95.20% (0.95199) | 98.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 94.73% (0.94728) | 98.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.06% (0.12063) | 95.18th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.06% (0.12063) | 94.79th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.06% (0.12063) | 89.20th | v2 (v2022.01.01) |
No CWE recorded.
References (22)
- http://blogs.adobe.com/psirt/?p=1330 x_refsource_CONFIRMBroken LinkVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html vendor-advisoryx_refsource_SUSEBroken Link
- http://rhn.redhat.com/errata/RHSA-2016-0610.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/bid/85856 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035491 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2016-1019 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1324353 Issue Tracking
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050 vendor-advisoryx_refsource_MSPatchThird Party AdvisoryVendor Advisory
- https://github.com/cisagov/vulnrichment/issues/196 issue-trackingIssue Tracking
- https://helpx.adobe.com/security/products/flash-player/apsa16-01.html x_refsource_CONFIRMVendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-10.html x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-1019
- https://security.gentoo.org/glsa/201606-08 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1019 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2016-1019
- https://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.html x_refsource_MISCBroken Link
Change history (3)
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- SSVC automatable changed from yes to
no