Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2022-05-25 — agencies required to remediate by 2022-06-15

CVE-2016-1010

HIGH

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe…

Published
Mar 12, 2016
Updated
Apr 22, 2026
Affected
0 pkgs
Patched
None yet
Exploits
2 known

EPSS Exploitation Probability

via FIRST.org ↗
12.7%probability of exploitation in next 30 days
Moderate Risk94th percentile0.00%
7.52%16.7%26.0%35.2%27.4%12.7%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.

Affected Products

7 products · 10 configurations
Application
airadobe
≤ 20.0.0.233
range
Application
air desktop runtimeadobe
≤ 20.0.0.260
range
Application
air sdkadobe
≤ 20.0.0.260
range
Application
air sdk \& compileradobe
≤ 20.0.0.260
range
Application
flash playeradobe
≤ 20.0.0.306
range
Application
flash player desktop runtimeadobe
≤ 20.2.2.306
range
Exploits & PoCs
2

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Frequently Asked Questions

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
O3 Security · Impact-Aware SCA

Is CVE-2016-1010 in your stack?

O3 detects CVE-2016-1010 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.