Vulnerability Name: | CVE-2012-4168 (CCN-77911) | ||||||||||||||||||||||||
Assigned: | 2012-08-21 | ||||||||||||||||||||||||
Published: | 2012-08-21 | ||||||||||||||||||||||||
Updated: | 2018-12-04 | ||||||||||||||||||||||||
Summary: | Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allow remote attackers to read content from a different domain via a crafted web site. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-4168 Source: CCN Type: Google Chrome Releases Stable Channel Update Source: HP Type: Mailing List, Third Party Advisory HPSBMU02948 Source: CCN Type: RHSA-2012-1173 Critical: flash-plugin security update Source: CCN Type: RHSA-2012-1203 Critical: flash-plugin security update Source: REDHAT Type: Third Party Advisory RHSA-2012:1203 Source: CCN Type: SA50354 Adobe Flash Player Multiple Vulnerabilities Source: CCN Type: SA50356 Google Chrome Adobe Flash Player Vulnerabilities Source: GENTOO Type: Third Party Advisory GLSA-201209-01 Source: CCN Type: Adobe Product Security Bulletin APSB12-19 Security updates available for Adobe Flash Player Source: CONFIRM Type: Patch, Vendor Advisory http://www.adobe.com/support/security/bulletins/apsb12-19.html Source: CCN Type: OSVDB ID: 84794 Adobe Flash Player / AIR Unspecified Cross-Domain Information Disclosure Source: CCN Type: BID-56197 Adobe Flash Player and AIR CVE-2012-4168 Cross Domain Information Disclosure Vulnerability Source: XF Type: UNKNOWN adobe-unspec-information-disc(77911) | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |