CVE-2012-0767

Confirmed PUBLISHED

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and...

Adobe · Flash Player
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.1 Medium

At a Glance

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.

windows cisa macos android linux
CVE Published
Feb 16, 2012
Exploitation Reported
Jun 08, 2022
CVSS
6.1 Medium
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2012:0265 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00014...
  • GLSA-201204-07 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201204-07.xml
  • RHSA-2012:0144 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2012-0144.html
  • 48265 secunia.com · Third-Party Advisory http://secunia.com/advisories/48265
  • 48819 secunia.com · Third-Party Advisory http://secunia.com/advisories/48819
Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.