Skip to main content

CVE detail

CVE-2012-0754

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVSS 8.1 · HighBuzz score 50.6KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 50.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 16.1 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
16.1
4 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
4 source links · newest first
  • Surgical malware attack agains US via IranSecurity Affairs

    Sometimes warfare operation and cyber crime are really difficult to distinguish, especially when the cyber scenario is related to country that is facing with rising political tension such as Iran. I refuse to call cyber criminals, a group of expert hackers who made himself the protagonist of a complex story from different points of view. The […]

    newssecurityaffairs.comMar 14, 2012, 11:14 AM
  • Just yesterday, SecurityWeek reported on a recent incident where senior military and government officials were duped into “friending” someone on Facebook that was pretending to be U.S. Admiral James Stavridis, NATO’s Supreme Allied Commander in Europe. That fake profile was believed to be setup by Chinese hackers interested in gathering email addresses and other information from military and government officials.

    newswww.securityweek.comMar 13, 2012, 11:55 AM
  • A new targeted email attack is exploiting interest in the Iranian nuclear program to trick people into opening booby-trapped Word documents that exploit a known Flash Player vulnerability to install malware. “There seems to be a new campaign underway using this new CVE-2012-0754 exploit,” said independent security researcher Mila Parkour in a blog post on […]

    newswww.csoonline.comMar 6, 2012, 3:00 PM
  • Flash vulnerability exploited to deliver malwareHelp Net Security

    Attackers are once again exploiting the public’s tendency for not keeping its software updated and its ongoing interest about Iran and its nuclear program to infect users with a backdoor Trojan. The threat, first flagged and described by security researcher Mila Parkour, comes in an email from a “William Abnett” with “Iran’s Oil and Nuclear Situation” in the subject line. The attached Iran’s Oil and Nuclear Situation.doc file contains Flash, which downloads a corrupted mp4 … More →

    newswww.helpnetsecurity.comMar 6, 2012, 9:20 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence