CVE-2011-2110 is a critical memory corruption vulnerability in Adobe Flash Player, affecting versions prior to 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 on Android. This flaw allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. With a CVSS score of 10.0, it is easily exploitable over the network with low complexity and no authentication, leading to complete compromise of confidentiality, integrity, and availability. The vulnerability was actively exploited in the wild in June 2011, and a Metasploit module exists, indicating readily available exploit code and significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.3.181.23CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
6.0.21.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.21.0:*:*:*:*:*:*:* | ||
6.0.79CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.79:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.