← Vulnerability feed

Vulnerability record · CVE-2016-1010 · published 12 March 2016

CVE-2016-1010: Adobe Flash Player and AIR integer overflow allows code execution

Adobe · Flash Player

Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that permits arbitrary code execution via unspecified vectors. The flaw affects Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X, before 11.2.202.577 on Linux, and AIR/SDK builds before 21.0.0.176. It matters because the affected products are end-of-life and the issue is listed in CISA KEV.

8.8 CVSS 3.1 High CISA KEV since 25 May 2022 EPSS 19% · top 2.7% CWE-190 · Integer overflow
8.8CVSS 3.1 base score, v2 9.3
19%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
17References
17 Jun 2026Last modified by NVD

Description

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 and confirmed exploitation via CISA KEV, tempered by the requirement for user interaction and the end-of-life status of the affected products.

What it is

Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that permits arbitrary code execution via unspecified vectors. The flaw affects Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X, before 11.2.202.577 on Linux, and AIR/SDK builds before 21.0.0.176. It matters because the affected products are end-of-life and the issue is listed in CISA KEV.

Impact

An attacker who triggers the overflow can execute arbitrary code in the context of the affected runtime, giving full compromise of confidentiality, integrity and availability per the CVSS vector. No privilege escalation beyond the runtime's own context is described.

Attack surface

The CVSS vector is network-reachable (AV:N) with low complexity and no privileges, but requires user interaction (UI:R), consistent with a victim opening crafted content in Flash Player or AIR. The description does not specify the exact vectors or delivery mechanism.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2022-05-25, indicating real-world exploitation; EPSS gives a 30-day probability of 0.194 (97th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor patch: upgrade Flash Player to 18.0.0.333 or later, 21.0.0.182 or later for 19.x-21.x, 11.2.202.577 or later on Linux, and AIR/AIR SDK/AIR SDK & Compiler to 21.0.0.176 or later.
  • Because Flash Player and AIR are end-of-life, disconnect or remove the affected products where they are still in use, per CISA's required action.
  • Block or disable Flash content in browsers and email clients, and restrict execution of AIR applications to trusted sources.
  • Where removal is not immediately possible, isolate systems running the affected runtimes and restrict their network access.

Detection

  • Hunt for hosts still running Flash Player or AIR versions below the fixed builds listed in Adobe APSB16-08.
  • Monitor for processes loading Flash/AIR runtime libraries spawning unexpected child processes or making outbound connections.
  • Review proxy and DNS logs for delivery of Flash content (.swf) from untrusted or newly registered domains.
  • Check endpoint telemetry for crashes or memory corruption events in Flash Player or AIR processes that may indicate exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-1010 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Adobe Flash Player and AIR Integer Overflow Vulnerability". Required action: The impacted products are end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/84308 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1035251 Broken LinkThird Party AdvisoryVDB Entry
https://helpx.adobe.com/security/products/flash-player/apsb16-08.html PatchVendor Advisory
https://security.gentoo.org/glsa/201603-07 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.html Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/84308 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1035251 Broken LinkThird Party AdvisoryVDB Entry
https://helpx.adobe.com/security/products/flash-player/apsb16-08.html PatchVendor Advisory
https://security.gentoo.org/glsa/201603-07 Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1010 US Government Resource

Track CVE-2016-1010 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2015-3043Adobe Flash Player memory corruption allows arbitrary code executionAdobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. Th…KEVEPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2016-1010), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.