Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.
Conclusion & alert: CVE-2012-0767 is rated Active Exploitation (77/100): CVSS Medium severity, with high exploitation likelihood (EPSS 6.74%, 93th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-06-08) affecting Adobe / Flash Player. cross-site scripting (CWE-79) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability · CISA KEV detail
: 2022-06-08
: 2022-06-22
: The impacted product is end-of-life and should be disconnected if still in use.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 14.91% | 6.74% | -8.18% |
| 2 | 2026-04-22 | 16.27% | 14.91% | -1.35% |
| 3 | 2026-01-31 | — | 16.27% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
normal | CVE-2012-0767: 1 GLSA(s) (201204-07), 1 atom(s) (www-plugins/adobe-flash); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2012-0767 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2012-0767 |
ubuntu
|
medium | CVE-2012-0767 medium priority: Ubuntu including 2 source packages (adobe-flashplugin, flashplugin-nonfree), 12 status rows across 6 suites (hardy, lucid, maverick, natty, oneiric, upstream): released 10, ignored 2. | https://ubuntu.com/security/CVE-2012-0767 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| adobe | flash_player | < 10.3.183.15 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| adobe | flash_player | >= 11.0, < 11.1.102.62 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| adobe | flash_player | < 11.1.111.6 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| adobe | flash_player | < 11.1.115.6 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00014.html | Broken Link |
| http://rhn.redhat.com/errata/RHSA-2012-0144.html | Third Party Advisory |
| http://secunia.com/advisories/48265 | Broken Link |
| http://secunia.com/advisories/48819 | Broken Link |
| http://security.gentoo.org/glsa/glsa-201204-07.xml | Third Party Advisory |
| http://www.adobe.com/support/security/bulletins/apsb12-03.html | Broken Link Patch Vendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14806 | Third Party Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15933 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0767 | US Government Resource |