Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.
2012-05-04T19:55:04.263
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | flash_player | < 10.3.183.19 | Yes |
Application | adobe | flash_player | ≤ 11.2.202.233 | Yes |
Operating System | apple | mac_os_x | - | No |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |
Application | adobe | flash_player | ≤ 11.1.111.8 | Yes |
Operating System | android | ≤ 2.3.7 | No | |
Operating System | android | ≤ 3.2.6 | No | |
Application | adobe | flash_player | ≤ 11.1.115.7 | Yes |
Operating System | android | ≤ 4.4.4 | No |