peter bassill · operator
$ cve CVE-2012-5054 JSON

CVE-2012-5054 KEV

8.8
HIGH · CVSS 3.1 · EPSS 21.2% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS21.19% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-190
On CISA KEVyes — remediate by 2022-06-22
Public exploitnone known
Published2012-09-24
Last modified2026-06-16

CISA KEV

NameAdobe Flash Player Integer Overflow Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (1)

VendorProduct
adobeflash player

References

→ the Explorer  ·  watch your stack  ·  NVD