peter bassill · operator
$ cve CVE-2012-0779 JSON

CVE-2012-0779 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 87.1% (pctl 100)

Patch early

A public exploit exists.

Description

Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS87.09% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2012-05-04
Last modified2026-06-16

Affected (5)

VendorProduct
adobeflash player
applemac os x
googleandroid
linuxlinux kernel
microsoftwindows

Public exploits

SourceTitleDate
exploit-dbAdobe Flash Player - Object Type Confusion (Metasploit)2012-06-25

References

→ the Explorer  ·  watch your stack  ·  NVD