CVE-2012-1535
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product is end-of-life and should be disconnected if still in use.
Added 2022-03-03Remediation due 2022-03-24
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.
7.8
CVSS
70.4%
EPSS (exploit prob.)
99th
EPSS percentile
2012-08-15
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-20CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | flash_player | < 11.3.300.271 |
| apple | mac_os_x | all versions |
| microsoft | windows | all versions |
| adobe | flash_player | < 11.2.202.238 |
| linux | linux_kernel | all versions |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_workstation | 5.0 |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.1 |
| suse | linux_enterprise_desktop | 10 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00012.html
- http://marc.info/?l=bugtraq&m=139455789818399&w=2
- http://rhn.redhat.com/errata/RHSA-2012-1203.html
- http://security.gentoo.org/glsa/glsa-201209-01.xml
- http://www.adobe.com/support/security/bulletins/apsb12-18.html
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00012.html
- http://marc.info/?l=bugtraq&m=139455789818399&w=2
- http://rhn.redhat.com/errata/RHSA-2012-1203.html
- http://security.gentoo.org/glsa/glsa-201209-01.xml
- http://www.adobe.com/support/security/bulletins/apsb12-18.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1535
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-1535