Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-2040 | First vendor Publication | 2012-06-08 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows local users to gain privileges via a Trojan horse executable file in an unspecified directory. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2040 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-426 | Untrusted Search Path |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20682 | |||
Oval ID: | oval:org.mitre.oval:def:20682 | ||
Title: | Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 and Adobe AIR before 3.3.0.3610 on Windows, allows local users to gain privileges via a Trojan horse executable file in an unspecified directory | ||
Description: | Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows local users to gain privileges via a Trojan horse executable file in an unspecified directory. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2012-2040 | Version: | 6 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2012 | Product(s): | Adobe Flash Player Adobe Air |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-12-13 | Name : SuSE Update for flash-player openSUSE-SU-2012:0723-1 (flash-player) File : nvt/gb_suse_2012_0723_1.nasl |
2012-11-26 | Name : FreeBSD Ports: linux-f10-flashplugin File : nvt/freebsd_linux-f10-flashplugin5.nasl |
2012-08-10 | Name : FreeBSD Ports: linux-f10-flashplugin File : nvt/freebsd_linux-f10-flashplugin3.nasl |
2012-08-10 | Name : Gentoo Security Advisory GLSA 201206-21 (Adobe Flash Player) File : nvt/glsa_201206_21.nasl |
2012-06-20 | Name : Adobe Flash Player Multiple Vulnerabilities June-2012 (Linux) File : nvt/gb_adobe_flash_player_mult_vuln_jun12_lin.nasl |
2012-06-20 | Name : Adobe Flash Player Multiple Vulnerabilities June-2012 (Mac OS X) File : nvt/gb_adobe_prdts_mult_vuln_jun12_macosx.nasl |
2012-06-20 | Name : Adobe Flash Player Multiple Vulnerabilities June-2012 (Windows) File : nvt/gb_adobe_prdts_mult_vuln_jun12_win.nasl |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2012-315.nasl - Type : ACT_GATHER_INFO |
2013-01-25 | Name : The remote SuSE 11 host is missing a security update. File : suse_11_flash-player-120610.nasl - Type : ACT_GATHER_INFO |
2012-11-06 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_36533a59277011e2bb44003067b2972c.nasl - Type : ACT_GATHER_INFO |
2012-06-25 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201206-21.nasl - Type : ACT_GATHER_INFO |
2012-06-12 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_flash-player-8182.nasl - Type : ACT_GATHER_INFO |
2012-06-11 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_38195f00b21511e18132003067b2972c.nasl - Type : ACT_GATHER_INFO |
2012-06-09 | Name : The remote Windows host has a browser plugin that is affected by multiple vul... File : flash_player_apsb12-14.nasl - Type : ACT_GATHER_INFO |
2012-06-09 | Name : The remote Mac OS X host has a browser plugin that is affected by multiple vu... File : macosx_flash_player_11_3_300_257.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:01:40 |
|
2024-11-28 12:29:43 |
|
2021-09-08 21:24:38 |
|
2020-08-14 00:22:44 |
|
2020-05-23 01:48:38 |
|
2020-05-23 00:33:29 |
|
2019-07-18 12:04:30 |
|
2019-06-18 12:04:17 |
|
2018-12-15 12:03:47 |
|
2018-10-30 12:05:00 |
|
2018-03-09 12:00:53 |
|
2018-01-05 09:23:15 |
|
2016-06-28 19:06:55 |
|
2016-04-26 21:45:28 |
|
2015-11-10 21:22:52 |
|
2014-06-14 13:32:50 |
|
2014-02-17 11:09:48 |
|
2013-05-10 22:38:09 |
|