← All CVEs

CVE-2012-0767

medium · 6.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-06-08Remediation due 2022-06-22

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.

6.1
CVSS
6.7%
EPSS (exploit prob.)
94th
EPSS percentile
2012-02-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
adobeflash_player< 10.3.183.15
adobeflash_player>= 11.0, < 11.1.102.62
applemac_os_xall versions
linuxlinux_kernelall versions
microsoftwindowsall versions
oraclesolarisall versions
adobeflash_player< 11.1.111.6
googleandroid>= 2.0, <= 3.2
adobeflash_player< 11.1.115.6
googleandroid4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-0767