CVE-2018-12824

CWE-125Out-of-bounds Read6 documents6 sources
Severity
5.9MEDIUM
EPSS
2.3%
top 15.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 14

Description

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages7 packages

CVEListV5adobe_flash_player_30.0.0.134_and_earlierAdobe Flash Player 30.0.0.134 and earlier
NVDadobe/flash_player30.0.0.154
Ubuntuflashplugin-nonfree< 30.0.0.154ubuntu0.14.04.1+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2qwg-3h4c-44rq: Adobe Flash Player 302022-05-14
CVEList
CVE-2018-12824: Adobe Flash Player 302018-08-29
OSV
CVE-2018-12824: Adobe Flash Player 302018-08-29

📋Vendor Advisories

1
Red Hat
flash-plugin: Information Disclosure vulnerabilities (APSB18-25)2018-08-14

💬Community

1
Bugzilla
CVE-2018-12824 CVE-2018-12826 CVE-2018-12827 flash-plugin: Information Disclosure vulnerabilities (APSB18-25)2018-08-14