CVE-2012-4168Sensitive Information Exposure in Adobe AIR

Severity
4.3MEDIUMNVD
EPSS
0.8%
top 26.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21
Latest updateMay 14

Description

Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allow remote attackers to read content from a different domain via a crafted web site.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDadobe/flash_player10.310.3.183.23+4
NVDadobe/air< 3.4.0.2540
NVDadobe/air_sdk< 3.4.0.2540

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g7fv-ffv7-x9gv: Adobe Flash Player before 102022-05-14
CVEList
CVE-2012-4168: Adobe Flash Player before 102012-08-21

📋Vendor Advisories

1
Red Hat
flash-plugin: cross-domain information leak flaw (APSB12-19)2012-08-21

💬Community

1
Bugzilla
CVE-2012-4168 flash-plugin: cross-domain information leak flaw (APSB12-19)2012-08-21
CVE-2012-4168 — Sensitive Information Exposure in Adobe | cvebase