Vulnerability Description
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | < 11.4.402.265 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.org/files/116435/Adobe-Flash-Player-Matrix3D-Integer-ExploitThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-19.htmlNot ApplicableVendor Advisory
- http://www.vupen.com/english/services/ba-index.phpBroken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78866Third Party AdvisoryVDB Entry
- http://packetstormsecurity.org/files/116435/Adobe-Flash-Player-Matrix3D-Integer-ExploitThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-19.htmlNot ApplicableVendor Advisory
- http://www.vupen.com/english/services/ba-index.phpBroken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78866Third Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-US Government Resource
FAQ
What is CVE-2012-5054?
CVE-2012-5054 is a vulnerability with a CVSS score of 8.8 (HIGH). Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.
How severe is CVE-2012-5054?
CVE-2012-5054 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-5054?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player.