CVE-2011-2110
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 86.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 86.42% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- adobe/flash player
- Source
- psirt@adobe.com
References
- http://secunia.com/advisories/44924
- http://secunia.com/advisories/44941
- http://secunia.com/advisories/44950
- http://secunia.com/advisories/44964
- http://secunia.com/advisories/48308
- http://www.adobe.com/support/security/bulletins/apsb11-18.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0869.html
- http://www.securitytracker.com/id?1025651
- http://www.us-cert.gov/cas/techalerts/TA11-166A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68029
- https://hermes.opensuse.org/messages/8782873
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14091
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16252
- http://secunia.com/advisories/44924
- http://secunia.com/advisories/44941
- http://secunia.com/advisories/44950
- http://secunia.com/advisories/44964
- http://secunia.com/advisories/48308
- http://www.adobe.com/support/security/bulletins/apsb11-18.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0869.html
- http://www.securitytracker.com/id?1025651
- http://www.us-cert.gov/cas/techalerts/TA11-166A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68029
- https://hermes.opensuse.org/messages/8782873
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14091
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16252
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.