CVE-2012-5286

critical
Published 2012-11-13 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than other Flash Player buffer overflow CVEs listed in APSB12-22.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — http://www.adobe.com/support/security/bulletins/apsb12-22.html

OS impact

OSVersionStatusFixed in
macos macosnot-affected
linux linux-kernelnot-affected

Application impact

VendorProductVersionsFixed
adobeflash_player{"endIncluding":"10.3.183.25"}
adobeflash_player10.1.85.3
adobeflash_player10.1.102.64
adobeflash_player10.2.152.26
adobeflash_player10.2.152.32
adobeflash_player10.2.153.1
adobeflash_player10.2.159.1
adobeflash_player10.3.181.14
adobeflash_player10.3.181.16
adobeflash_player10.3.181.22
adobeflash_player10.3.181.26
adobeflash_player10.3.181.34
adobeflash_player10.3.183.5
adobeflash_player10.3.183.7
adobeflash_player10.3.183.10
adobeflash_player10.3.183.11
adobeflash_player10.3.183.15
adobeflash_player10.3.183.16
adobeflash_player10.3.183.18
adobeflash_player10.3.183.20
adobeflash_player10.3.183.23
adobeflash_player11.0.1.152
adobeflash_player11.1.102.55
adobeflash_player11.1.102.62
adobeflash_player11.1.102.63
adobeflash_player11.2.202.223
adobeflash_player11.2.202.228
adobeflash_player11.2.202.233
adobeflash_player11.2.202.235
adobeflash_player11.2.202.238
adobeflash_player11.2.202.243
adobeflash_player11.3.300.257
adobeflash_player11.3.300.262
adobeflash_player11.3.300.265
adobeflash_player11.3.300.268
adobeflash_player11.3.300.271
adobeflash_player11.3.300.273
adobeflash_player11.4.402.265
adobeflash_player11.4.402.278
adobeflash_player11.4.402.287
adobeflash_player11.0
adobeflash_player11.0.1.153
adobeflash_player11.1
adobeflash_player_for_android{"endIncluding":"11.1.111.16"}
adobeflash_player_for_android10.1.106.17
adobeflash_player_for_android10.2.157.51
adobeflash_player_for_android10.3.186.7
adobeflash_player_for_android11.0.1.153
adobeflash_player_for_android11.1.102.59
adobeflash_player_for_android11.1.111.5
adobeflash_player_for_android11.1.111.7
adobeflash_player_for_android11.1.111.8
adobeflash_player_for_android11.1.111.9
adobeflash_player_for_android11.1.111.10
adobeflash_player_for_android11.1.112.60
adobeflash_player_for_android11.1.112.61
adobeflash_player_for_android11.1.115.7
adobeflash_player_for_android11.1.115.8
adobeflash_player_for_android11.1.115.11
adobeflash_player_for_android11.1.115.12
adobeadobe_air{"endIncluding":"3.4.0.2540"}
adobeadobe_air1.0
adobeadobe_air1.0.1
adobeadobe_air1.0.8.4990
adobeadobe_air1.0.4990
adobeadobe_air1.1
adobeadobe_air1.1.0.5790
adobeadobe_air1.5
adobeadobe_air1.5.0.7220
adobeadobe_air1.5.1
adobeadobe_air1.5.1.8210
adobeadobe_air1.5.2
adobeadobe_air1.5.3
adobeadobe_air1.5.3.9120
adobeadobe_air1.5.3.9130
adobeadobe_air2.0.2
adobeadobe_air2.0.2.12610
adobeadobe_air2.0.3
adobeadobe_air2.0.3.13070
adobeadobe_air2.0.4
adobeadobe_air2.5.0.16600
adobeadobe_air2.5.1.17730
adobeadobe_air2.6
adobeadobe_air2.6.0.19120
adobeadobe_air2.6.0.19140
adobeadobe_air2.7
adobeadobe_air2.7.0.1948
adobeadobe_air2.7.0.1953
adobeadobe_air2.7.0.19480
adobeadobe_air2.7.0.19530
adobeadobe_air2.7.1
adobeadobe_air2.7.1.19610
adobeadobe_air3.0.0.408
adobeadobe_air3.0.0.4080
adobeadobe_air3.1.0.485
adobeadobe_air3.1.0.488
adobeadobe_air3.1.0.4880
adobeadobe_air3.2.0.207
adobeadobe_air3.2.0.2070
adobeadobe_air3.3.0.3670
adobeadobe_air_sdk{"endIncluding":"3.4.0.2540"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.