CVE-2012-5054

EUVD-2012-4978
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
adobeflash_player
𝑥
< 11.4.402.265
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flashplugin-nonfree
hardy
ignored
lucid
Fixed 11.2.202.238ubuntu0.10.04.1
released
natty
Fixed 11.2.202.238ubuntu0.11.04.1
released
oneiric
Fixed 11.2.202.238ubuntu0.11.10.1
released
precise
Fixed 11.2.202.238ubuntu0.12.04.1
released