CVE-2012-5054
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Flash Player Integer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 21% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-190
מוצרים מושפעים
adobe: flash player
קישורים
- http://www.adobe.com/support/security/bulletins/apsb12-19.html Not ApplicableVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-19.html Not ApplicableVendor Advisory
- http://packetstormsecurity.org/files/116435/Adobe-Flash-Player-Matrix3D-Intege… ExploitThird Party Advisory
- http://packetstormsecurity.org/files/116435/Adobe-Flash-Player-Matrix3D-Intege… ExploitThird Party Advisory
- http://www.vupen.com/english/services/ba-index.php Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78866 Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/services/ba-index.php Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78866 Third Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource