CVE-2012-0779 is an object confusion vulnerability in Adobe Flash Player, affecting versions before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux, as well as various Android versions. This critical vulnerability carries a CVSS score of 9.3, indicating a network-based attack with high complexity, allowing unauthenticated attackers to achieve complete compromise of confidentiality, integrity, and availability. It was actively exploited in the wild in May 2012, with Metasploit modules available and significant community discussion and media coverage confirming its widespread impact and use in targeted attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.3, < 10.3.183.19CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.2, <= 11.2.202.233CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.1, <= 11.1.111.8CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.1, <= 11.1.115.7CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.