peter bassill · operator
$ cve CVE-2011-2140 JSON

CVE-2011-2140 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 82.3% (pctl 100)

Patch early

A public exploit exists.

Description

Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135, CVE-2011-2417, and CVE-2011-2425.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS82.26% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2011-08-10
Last modified2026-06-16

Affected (7)

VendorProduct
adobeadobe air
adobeflash player
applemac os x
googleandroid
linuxlinux kernel
microsoftwindows
sunsunos

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD