{
  "id": "CVE-2012-2034",
  "url": "https://spydr.io/cve/CVE-2012-2034",
  "published": "2012-06-09T00:55:00.987Z",
  "modified": "2026-06-16T23:40:50.083Z",
  "score": 7.5,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.078,
  "epss_percentile": 0.94516,
  "exploited": true,
  "kev": {
    "added": "2022-03-28",
    "due": "2022-04-18",
    "action": "The impacted product is end-of-life and should be disconnected if still in use.",
    "ransomware": "Unknown",
    "name": "Adobe Flash Player Memory Corruption Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2012-2034"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "adobe",
    "opensuse",
    "suse",
    "redhat"
  ],
  "products": [
    "adobe flash player",
    "adobe air",
    "opensuse",
    "suse linux enterprise desktop",
    "redhat enterprise linux desktop",
    "redhat enterprise linux eus",
    "redhat enterprise linux server",
    "redhat enterprise linux server aus",
    "redhat enterprise linux workstation"
  ],
  "cwes": [
    "CWE-119"
  ],
  "description": "Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00006.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00007.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-0722.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.adobe.com/support/security/bulletins/apsb12-14.html",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-2034",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2012-2034",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
