Evidence dossier

CVE-2012-2034

CVE-2012-2034

64.383.8Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.

State
PUBLISHED
Published
Jun 9, 2012
Updated
Oct 22, 2025
Evidence coverage
72%
CISA KEVCatalog member

The impacted product is end-of-life and should be disconnected if still in use.

FIRST EPSS7.80%

2026-07-18 · v2026.06.15 · percentile 94.0%

Source stateConflict visible

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

adobeoriginal assertion
container

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

CISA KEVoriginal assertion
observed_exploitation

Adobe Flash Player Memory Corruption Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.078000000000; percentile 0.939960000000

Applicability

Cited product scope

Trace impact →
25Underlying assertions
13Canonical products
17Target assertions
8Constraint assertions

Grouped from 10 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

14 scope groups

adobe · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · APPLICATIONadobeairVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.2.0.2070)Canonical identity product-75196b987f92f714b36c2af5dd8388f222a14e51d452c08b35874c8edcc387ealinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.2.0.2070
    Match ID
    eff9fcbd-a543-48cf-8332-27154b491c5c
NVD CPE · APPLICATIONadobeflash_playerVulnerable target · 3 assertions
Any version (unconstrained) (<= 11.1.111.9); Any version (unconstrained) (<= 11.1.115.8); Any version (unconstrained) (<= 11.2.202.235)Canonical identity product-1f43dd2fb9df2cb64d1a717194e5325cf3f2d14dbb24ebbb35d9226a3dc1cbe7linked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 11.1.115.8
    Match ID
    f4ee60c5-c066-4268-a90d-86bb3862a2a0
  2. cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 11.2.202.235
    Match ID
    672f3490-4072-4110-9cdd-0d6cb2379af3
  3. cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 11.1.111.9
    Match ID
    a6aa2009-e921-4f32-ab61-07cae2c6b93f
NVD CPE · OPERATING SYSTEMapplemacosEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-d6f53ba981bb58ea2b0d24855b8ff4a18555e3a17a9dce0d38460a69537bbc63linked exact
constrained
Inspect 2 returned assertions
  1. cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    387021a0-af36-463c-a605-32ea7dac172e
  2. cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    387021a0-af36-463c-a605-32ea7dac172e
NVD CPE · OPERATING SYSTEMgoogleandroidEnvironmental constraint · 3 assertions
Any version (unconstrained) (>= 2.0, <= 3.2.6); Any version (unconstrained) (>= 4.0, <= 4.4.4); Version not applicableCanonical identity product-92706ad297e0bcadcd6adc374dd80eb27012c37cd92e19cf49650461139673eclinked exact
constrained
Inspect 3 returned assertions
  1. cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    from including 2.0; through including 3.2.6
    Match ID
    1c031663-1513-4a3c-a398-2179893416a8
  2. cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f8b9fec8-73b6-43b8-b24e-1f7c20d91d26
  3. cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    from including 4.0; through including 4.4.4
    Match ID
    539fc1e0-6987-48ee-8fe9-7a27d4c3b69a
NVD CPE · OPERATING SYSTEMlinuxlinux_kernelEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    703af700-7a70-47e2-bc3a-7fd03b3ca9c1
NVD CPE · OPERATING SYSTEMmicrosoftwindowsEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-6a798dc931affc038ba266631a506d54b455ffebd96b4fae68f77b6bd7aef178linked exact
constrained
Inspect 2 returned assertions
  1. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
  2. cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2572d17-1de6-457b-99cc-64afd54487ea
NVD CPE · OPERATING SYSTEMopensuseopensuseVulnerable target · 2 assertions
Version 11.4; Version 12.1Canonical identity product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdlinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de554781-1eb9-446e-911f-6c11970c47f4
  2. cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ebb2c482-d2a4-48b3-ace7-e1dfdcc409b5
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_desktopVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aelinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
  2. cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    133aafa7-af42-4d7b-8822-aa2e85611bf5
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 1 assertions
Version 6.2Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_eus:6.2:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c0554c89-3716-49f3-bfae-e008d5e4e29c
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_serverVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dealinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    54d669d4-6d7e-449d-80c1-28fa44f06ffe
  2. cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9bbcd86a-e6c7-4444-9d74-f861084090f0
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_ausVulnerable target · 1 assertions
Version 6.2Canonical identity product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaelinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad6d0378-f0f4-4aaa-80af-8287c790ec96
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_workstationVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0ac5cd5-6e58-433c-9eb3-6dfe5656463e
  2. cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5ed5807-55b7-47c5-97a6-03233f4fbc3a
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_desktopVulnerable target · 3 assertions
Version 10; Version 11Canonical identity product-908c58b965f5cdd7f6621821fd6c68d62c5a5ce89de01a9e91af7286e0b17d41linked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f0545634-ec4a-48e8-ab3d-49802fb11758
  2. cpe:2.3:o:suse:linux_enterprise_desktop:11:sp1:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    60fbdd82-691c-4d9d-b71b-f9aff6931b53
  3. cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00720d8c-3ff3-4b1c-b74b-91f01a544399

Assessments

CVSS by origin

7.5
nvd@nist.govCVSS 3.1 · role PrimaryCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
9.3
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:M/Au:N/C:C/I:C/A:C
7.5
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.