← All CVEs

CVE-2012-2034

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-03-28Remediation due 2022-04-18

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.

7.5
CVSS
7.8%
EPSS (exploit prob.)
94th
EPSS percentile
2012-06-09
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
adobeflash_player<= 11.2.202.235
applemacosall versions
linuxlinux_kernelall versions
microsoftwindowsall versions
adobeflash_player<= 11.1.115.8
googleandroid>= 4.0, <= 4.4.4
adobeflash_player<= 11.1.111.9
googleandroid>= 2.0, <= 3.2.6
adobeair<= 3.2.0.2070
applemacosall versions
googleandroidall versions
microsoftwindowsall versions
opensuseopensuse11.4
opensuseopensuse12.1
suselinux_enterprise_desktop10
suselinux_enterprise_desktop11
suselinux_enterprise_desktop11
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.2
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus6.2
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-2034