CVE-2012-4168 is a cross-domain content reading vulnerability affecting multiple versions of Adobe Flash Player and Adobe AIR across various operating systems, including Windows, macOS, Linux, and Android. This medium-complexity vulnerability allows remote attackers to read content from a different domain by enticing a user to visit a crafted website. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community discussion and media coverage, indicating awareness. The CVSS score of 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) reflects its potential for partial confidentiality impact without affecting integrity or availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.3, < 10.3.183.23CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.4, < 11.4.402.265CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.2, < 11.2.202.238CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1.111.16CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1.115.17CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.