CVE-2012-0767 is a critical Cross-site Scripting (XSS) vulnerability, also known as Universal XSS (UXSS), affecting Adobe Flash Player across multiple platforms including Windows, Mac OS X, Linux, Solaris, and Android. This flaw allows remote attackers to inject arbitrary web script or HTML. With a CVSS score of 6.1 (MEDIUM) and a FAUCET Risk Score of 99/100, the vulnerability is easily exploitable via network access with low attack complexity, requiring user interaction to achieve partial confidentiality and integrity impacts. Notably, this CVE was actively exploited in the wild in February 2012 and is listed in CISA's KEV catalog. Despite its age, it continues to garner significant community discussion, though no public exploit code is available via Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.3.183.15CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.1.102.62CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 11.1.111.6CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 11.1.115.6CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.