CVE-2012-0767
medium · 6.1Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product is end-of-life and should be disconnected if still in use.
Added 2022-06-08Remediation due 2022-06-22
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.
6.1
CVSS
6.7%
EPSS (exploit prob.)
94th
EPSS percentile
2012-02-16
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | flash_player | < 10.3.183.15 |
| adobe | flash_player | >= 11.0, < 11.1.102.62 |
| apple | mac_os_x | all versions |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
| oracle | solaris | all versions |
| adobe | flash_player | < 11.1.111.6 |
| android | >= 2.0, <= 3.2 | |
| adobe | flash_player | < 11.1.115.6 |
| android | 4.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00014.html
- http://rhn.redhat.com/errata/RHSA-2012-0144.html
- http://secunia.com/advisories/48265
- http://secunia.com/advisories/48819
- http://security.gentoo.org/glsa/glsa-201204-07.xml
- http://www.adobe.com/support/security/bulletins/apsb12-03.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14806
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15933
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00014.html
- http://rhn.redhat.com/errata/RHSA-2012-0144.html
- http://secunia.com/advisories/48265
- http://secunia.com/advisories/48819
- http://security.gentoo.org/glsa/glsa-201204-07.xml
- http://www.adobe.com/support/security/bulletins/apsb12-03.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14806
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15933
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0767
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-0767