CVE-2012-2034
high · 7.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product is end-of-life and should be disconnected if still in use.
Added 2022-03-28Remediation due 2022-04-18
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.
7.5
CVSS
7.8%
EPSS (exploit prob.)
94th
EPSS percentile
2012-06-09
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | flash_player | <= 11.2.202.235 |
| apple | macos | all versions |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
| adobe | flash_player | <= 11.1.115.8 |
| android | >= 4.0, <= 4.4.4 | |
| adobe | flash_player | <= 11.1.111.9 |
| android | >= 2.0, <= 3.2.6 | |
| adobe | air | <= 3.2.0.2070 |
| apple | macos | all versions |
| android | all versions | |
| microsoft | windows | all versions |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.1 |
| suse | linux_enterprise_desktop | 10 |
| suse | linux_enterprise_desktop | 11 |
| suse | linux_enterprise_desktop | 11 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 6.2 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_aus | 6.2 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00007.html
- http://rhn.redhat.com/errata/RHSA-2012-0722.html
- http://www.adobe.com/support/security/bulletins/apsb12-14.html
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00007.html
- http://rhn.redhat.com/errata/RHSA-2012-0722.html
- http://www.adobe.com/support/security/bulletins/apsb12-14.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-2034
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-2034