MEDIUM · 4.3

CVE-2012-4168

Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and bef...

Vulnerability Description

Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allow remote attackers to read content from a different domain via a crafted web site.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AdobeFlash Player>= 10.3, < 10.3.183.23
AppleMac Os X-
MicrosoftWindows-
LinuxLinux Kernel-
GoogleAndroid>= 2.0, <= 2.3.7
AdobeAir< 3.4.0.2540
AdobeAir Sdk< 3.4.0.2540

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4168?

CVE-2012-4168 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and bef...

How severe is CVE-2012-4168?

CVE-2012-4168 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4168?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Apple Mac Os X, Microsoft Windows, Linux Linux Kernel, Google Android.