CVE-2011-2140 is a critical memory corruption vulnerability in Adobe Flash Player and AIR across Windows, Mac OS X, Linux, Solaris, and Android platforms, allowing for arbitrary code execution or denial of service. With a CVSS score of 10.0 and a FAUCET Risk Score of 100/100, it represents a severe threat due to its network-exploitable nature and low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, multiple public exploits exist, including Metasploit modules and ExploitDB entries, indicating readily available attack tools. The vulnerability has garnered significant community discussion and media coverage, suggesting widespread awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.3.181.36CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
6.0.21.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.21.0:*:*:*:*:*:*:* | ||
6.0.79CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.79:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.