CVE-2012-0754
adobe flash player
Published 16 Feb 2012 · updated 16 Jun 2026 · Analyzed
8.1 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 8 Jun 2022, with a remediation deadline of 22 Jun 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
References
- lists.opensuse.org/opensuse-security-announce/2012-02/msg00014.html · Broken Link
- rhn.redhat.com/errata/RHSA-2012-0144.html · Third Party Advisory
- secunia.com/advisories/48265 · Broken Link
- secunia.com/advisories/48819 · Broken Link
- security.gentoo.org/glsa/glsa-201204-07.xml · Third Party Advisory
- www.adobe.com/support/security/bulletins/apsb12-03.html · Broken Link, Patch, Vendor Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15030 · Third Party Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15973 · Third Party Advisory
- github.com/cisagov/vulnrichment/issues/196 · Issue Tracking
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0754 · US Government Resource