CVE-2011-2415
high · 10Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2134, CVE-2011-2137, and CVE-2011-2414.
10
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2011-08-10
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | flash_player | <= 10.3.181.36 |
| adobe | flash_player | 6.0.21.0 |
| adobe | flash_player | 6.0.79 |
| adobe | flash_player | 7.0 |
| adobe | flash_player | 7.0.1 |
| adobe | flash_player | 7.0.14.0 |
| adobe | flash_player | 7.0.19.0 |
| adobe | flash_player | 7.0.24.0 |
| adobe | flash_player | 7.0.25 |
| adobe | flash_player | 7.0.53.0 |
| adobe | flash_player | 7.0.60.0 |
| adobe | flash_player | 7.0.61.0 |
| adobe | flash_player | 7.0.63 |
| adobe | flash_player | 7.0.66.0 |
| adobe | flash_player | 7.0.67.0 |
| adobe | flash_player | 7.0.68.0 |
| adobe | flash_player | 7.0.69.0 |
| adobe | flash_player | 7.0.70.0 |
| adobe | flash_player | 7.0.73.0 |
| adobe | flash_player | 7.1 |
| adobe | flash_player | 7.1.1 |
| adobe | flash_player | 7.2 |
| adobe | flash_player | 8.0 |
| adobe | flash_player | 8.0.22.0 |
| adobe | flash_player | 8.0.24.0 |
| adobe | flash_player | 8.0.33.0 |
| adobe | flash_player | 8.0.34.0 |
| adobe | flash_player | 8.0.35.0 |
| adobe | flash_player | 8.0.39.0 |
| adobe | flash_player | 8.0.42.0 |
| adobe | flash_player | 9.0 |
| adobe | flash_player | 9.0.16 |
| adobe | flash_player | 9.0.18d60 |
| adobe | flash_player | 9.0.20 |
| adobe | flash_player | 9.0.20.0 |
| adobe | flash_player | 9.0.28 |
| adobe | flash_player | 9.0.28.0 |
| adobe | flash_player | 9.0.31 |
| adobe | flash_player | 9.0.31.0 |
| adobe | flash_player | 9.0.45.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00008.html
- http://secunia.com/advisories/48308
- http://www.adobe.com/support/security/bulletins/apsb11-21.html
- http://www.redhat.com/support/errata/RHSA-2011-1144.html
- http://www.securityfocus.com/bid/49077
- http://www.us-cert.gov/cas/techalerts/TA11-222A.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13940
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16070
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00008.html
- http://secunia.com/advisories/48308
- http://www.adobe.com/support/security/bulletins/apsb11-21.html
- http://www.redhat.com/support/errata/RHSA-2011-1144.html
- http://www.securityfocus.com/bid/49077
- http://www.us-cert.gov/cas/techalerts/TA11-222A.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13940
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16070
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-2415