CVE-2011-0628 is an integer overflow vulnerability in Adobe Flash Player versions prior to 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.185.21 on Android. This flaw allows remote attackers to execute arbitrary code by manipulating ActionScript to improperly handle large array objects. The vulnerability carries a critical CVSS score of 9.3, indicating a high severity. It can be exploited remotely with medium attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability of affected systems. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.159.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
6.0.21.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.21.0:*:*:*:*:*:*:* | ||
6.0.79CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:6.0.79:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.