peter bassill · operator
$ cve CVE-2012-0767 JSON

CVE-2012-0767 KEV

6.1
MEDIUM · CVSS 3.1 · EPSS 6.4% (pctl 93)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS6.42% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-79
On CISA KEVyes — remediate by 2022-06-22
Public exploitnone known
Published2012-02-16
Last modified2026-06-16

CISA KEV

NameAdobe Flash Player Cross-Site Scripting (XSS) Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (6)

VendorProduct
adobeflash player
applemac os x
googleandroid
linuxlinux kernel
microsoftwindows
oraclesolaris

References

→ the Explorer  ·  watch your stack  ·  NVD