CVE-2011-0627 describes a critical memory corruption vulnerability in Adobe Flash Player versions prior to 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris, and prior to 10.3.185.21 on Android. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through specially crafted Flash content. With a CVSS score of 9.3, it is highly severe, requiring no authentication and moderate attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code is available in Metasploit, Nuclei, or ExploitDB, there were indications of in-the-wild exploitation via Microsoft Office documents embedding SWF files, and it garnered significant community discussion and media coverage at the time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.159.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
6.0.21.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.21.0:*:*:*:*:*:*:* | ||
6.0.79CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.79:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.