{"api_version":"1","generated_at":"2026-07-23T12:14:39+00:00","cve":"CVE-2011-0611","urls":{"html":"https://cve.report/CVE-2011-0611","api":"https://cve.report/api/cve/CVE-2011-0611.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0611","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0611"},"summary":{"title":"CVE-2011-0611","description":"Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a \"group of included constants,\" object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.","state":"PUBLISHED","assigner":"adobe","published_at":"2011-04-13 14:55:01","updated_at":"2026-04-21 20:30:01"},"problem_types":["CWE-843","n/a","CWE-843 CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2011/0923","name":"http://www.vupen.com/english/advisories/2011/0923","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/advisories/apsa11-02.html","name":"http://www.adobe.com/support/security/advisories/apsa11-02.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Adobe - Security Advisories: APSA11-02 - Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html","name":"http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"BugiX - Security Research: CVE-2011-0611 Adobe Flash Zero Day embeded in DOC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0922","name":"http://www.vupen.com/english/advisories/2011/0922","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8292","name":"http://securityreason.com/securityalert/8292","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1025325","name":"http://www.securitytracker.com/id?1025325","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Adobe Acrobat/Reader 'Authplay.dll' Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1025324","name":"http://www.securitytracker.com/id?1025324","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Adobe Flash Player Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/44119","name":"http://secunia.com/advisories/44119","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Adobe Flash Player SharedObject Type Confusion Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb11-07.html","name":"http://www.adobe.com/support/security/bulletins/apsb11-07.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Adobe - Security Bulletins: APSB11-07 - Security update available for Adobe Flash Player","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/17175","name":"http://www.exploit-db.com/exploits/17175","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Adobe Flash Player 10.2.153.1 SWF Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0451.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0451.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66681","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66681","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0611","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0611","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://secunia.com/blog/210/","name":"http://secunia.com/blog/210/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"404 | Flexera Blog","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/44149","name":"http://secunia.com/advisories/44149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Adobe Reader/Acrobat Two Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx","name":"http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Analysis of the CVE-2011-0611 Adobe Flash Player vulnerability exploitation - Microsoft Malware Protection Center - Site Home - TechNet Blogs","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html","name":"http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"Chrome Releases: Stable Channel Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html","name":"http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"],"title":"contagio: Apr. 8 CVE-2011-0611 Flash Player Zero day - SWF in DOC/ XLS - Disentangling Industrial Policy..","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb11-08.html","name":"http://www.adobe.com/support/security/bulletins/apsb11-08.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Adobe-Security Bulletins: APSB11-08 - Security update available for Adobe Reader and Acrobat","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8204","name":"http://securityreason.com/securityalert/8204","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0924","name":"http://www.vupen.com/english/advisories/2011/0924","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/230057","name":"http://www.kb.cert.org/vuls/id/230057","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#230057 - Adobe Flash Player contains unspecified code execution vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/44141","name":"http://secunia.com/advisories/44141","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Google Chrome Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html","name":"http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch"],"title":"[security-announce] SUSE Security Announcement: flash-player (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/47314","name":"http://www.securityfocus.com/bid/47314","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Adobe Flash Player CVE-2011-0611 'SWF' File Remote Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0611","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0611","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]},{"source":"ADP","vendor":"adobe","product":"flash_player","version":"affected 10.2.154.27 custom","platforms":[]},{"source":"ADP","vendor":"adobe","product":"air","version":"affected 2.6.19140 custom","platforms":[]},{"source":"ADP","vendor":"adobe","product":"reader","version":"affected 9.0 9.4.4 custom","platforms":[]},{"source":"ADP","vendor":"adobe","product":"reader","version":"affected 10.0 10.0.3 custom","platforms":[]},{"source":"ADP","vendor":"adobe","product":"acrobat","version":"affected 10.0 10.0.3 custom","platforms":[]},{"source":"ADP","vendor":"adobe","product":"acrobat","version":"affected 9.0 9.4.4 custom","platforms":[]}],"timeline":[{"source":"ADP","time":"2022-03-03T00:00:00.000Z","lang":"en","value":"CVE-2011-0611 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"611","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat_reader","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"1","versionEndIncluding":"10.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat_reader","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"1","versionEndIncluding":"10.2.156.12","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"611","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"oracle","cpe5":"solaris","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2011","cve_id":"611","cve":"CVE-2011-0611","vendorProject":"Adobe","product":"Flash Player","vulnerabilityName":"Adobe Flash Player Remote Code Execution Vulnerability","dateAdded":"2022-03-03","shortDescription":"Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.","requiredAction":"The impacted product is end-of-life and should be disconnected if still in use.","dueDate":"2022-03-24","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2011-0611","cwes":"CWE-843","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2011","cve_id":"611","cve":"CVE-2011-0611","epss":"0.994100000","percentile":"0.999370000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"affected":[{"cpes":["cpe:2.3:a:adobe:flash_player:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"flash_player","vendor":"adobe","versions":[{"lessThan":"10.2.154.27","status":"affected","version":"0","versionType":"custom"}]},{"cpes":["cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"air","vendor":"adobe","versions":[{"lessThan":"2.6.19140","status":"affected","version":"0","versionType":"custom"}]},{"cpes":["cpe:2.3:a:adobe:reader:9.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"reader","vendor":"adobe","versions":[{"lessThan":"9.4.4","status":"affected","version":"9.0","versionType":"custom"}]},{"cpes":["cpe:2.3:a:adobe:reader:10.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"reader","vendor":"adobe","versions":[{"lessThan":"10.0.3","status":"affected","version":"10.0","versionType":"custom"}]},{"cpes":["cpe:2.3:a:adobe:acrobat:10.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"acrobat","vendor":"adobe","versions":[{"lessThan":"10.0.3","status":"affected","version":"10.0","versionType":"custom"}]},{"cpes":["cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"acrobat","vendor":"adobe","versions":[{"lessThan":"9.4.4","status":"affected","version":"9.0","versionType":"custom"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2011-0611","options":[{"Exploitation":"active"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2024-02-02T14:05:34.031031Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2022-03-03","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0611"},"type":"kev"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-843","description":"CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-22T00:05:49.821Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0611"}],"timeline":[{"lang":"en","time":"2022-03-03T00:00:00.000Z","value":"CVE-2011-0611 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2024-08-06T21:58:26.000Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html"},{"name":"oval:org.mitre.oval:def:14175","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175"},{"name":"47314","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/47314"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/blog/210/"},{"name":"8204","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8204"},{"name":"ADV-2011-0922","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0922"},{"name":"RHSA-2011:0451","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0451.html"},{"name":"SUSE-SA:2011:018","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb11-07.html"},{"name":"8292","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8292"},{"name":"44149","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/44149"},{"name":"44141","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/44141"},{"name":"adobe-flash-swf-doc-ce(66681)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66681"},{"name":"ADV-2011-0924","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0924"},{"name":"1025325","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025325"},{"name":"17175","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/17175"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx"},{"name":"44119","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/44119"},{"name":"VU#230057","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/230057"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html"},{"name":"ADV-2011-0923","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0923"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/advisories/apsa11-02.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb11-08.html"},{"name":"1025324","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025324"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-04-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a \"group of included constants,\" object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"tags":["x_refsource_MISC"],"url":"http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html"},{"name":"oval:org.mitre.oval:def:14175","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175"},{"name":"47314","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/47314"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/blog/210/"},{"name":"8204","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8204"},{"name":"ADV-2011-0922","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0922"},{"name":"RHSA-2011:0451","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0451.html"},{"name":"SUSE-SA:2011:018","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb11-07.html"},{"name":"8292","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8292"},{"name":"44149","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/44149"},{"name":"44141","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/44141"},{"name":"adobe-flash-swf-doc-ce(66681)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66681"},{"name":"ADV-2011-0924","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0924"},{"name":"1025325","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025325"},{"name":"17175","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/17175"},{"tags":["x_refsource_MISC"],"url":"http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx"},{"name":"44119","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/44119"},{"name":"VU#230057","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/230057"},{"tags":["x_refsource_MISC"],"url":"http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html"},{"name":"ADV-2011-0923","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0923"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/advisories/apsa11-02.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb11-08.html"},{"name":"1025324","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025324"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2011-0611","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a \"group of included constants,\" object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html","refsource":"MISC","url":"http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html"},{"name":"oval:org.mitre.oval:def:14175","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175"},{"name":"47314","refsource":"BID","url":"http://www.securityfocus.com/bid/47314"},{"name":"http://secunia.com/blog/210/","refsource":"MISC","url":"http://secunia.com/blog/210/"},{"name":"8204","refsource":"SREASON","url":"http://securityreason.com/securityalert/8204"},{"name":"ADV-2011-0922","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0922"},{"name":"RHSA-2011:0451","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2011-0451.html"},{"name":"SUSE-SA:2011:018","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html"},{"name":"http://www.adobe.com/support/security/bulletins/apsb11-07.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb11-07.html"},{"name":"8292","refsource":"SREASON","url":"http://securityreason.com/securityalert/8292"},{"name":"44149","refsource":"SECUNIA","url":"http://secunia.com/advisories/44149"},{"name":"44141","refsource":"SECUNIA","url":"http://secunia.com/advisories/44141"},{"name":"adobe-flash-swf-doc-ce(66681)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66681"},{"name":"ADV-2011-0924","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0924"},{"name":"1025325","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025325"},{"name":"17175","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/17175"},{"name":"http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx","refsource":"MISC","url":"http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx"},{"name":"44119","refsource":"SECUNIA","url":"http://secunia.com/advisories/44119"},{"name":"VU#230057","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/230057"},{"name":"http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html","refsource":"MISC","url":"http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html"},{"name":"ADV-2011-0923","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0923"},{"name":"http://www.adobe.com/support/security/advisories/apsa11-02.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/advisories/apsa11-02.html"},{"name":"http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html"},{"name":"http://www.adobe.com/support/security/bulletins/apsb11-08.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb11-08.html"},{"name":"1025324","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025324"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2011-0611","datePublished":"2011-04-13T14:00:00.000Z","dateReserved":"2011-01-20T00:00:00.000Z","dateUpdated":"2025-10-22T00:05:49.821Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-04-13 14:55:01","lastModifiedDate":"2026-04-21 20:30:01","problem_types":["CWE-843","n/a","CWE-843 CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionEndExcluding":"10.2.154.27","matchCriteriaId":"FE4E1BEC-9158-405E-BCD1-0D354FFFC141"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"},{"vulnerable":false,"criteria":"cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*","matchCriteriaId":"91F372EA-3A78-4703-A457-751B2C98D796"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionEndIncluding":"10.2.156.12","matchCriteriaId":"46059035-6EA4-4D6F-800C-CEB9D394B933"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.4.4","matchCriteriaId":"E3A97142-27DF-46DD-9708-1CA202B7565C"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndIncluding":"10.0.1","matchCriteriaId":"43ADEFB3-9252-48C1-A6D5-BD2EE48A0E56"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:*","versionEndExcluding":"2.6.19140","matchCriteriaId":"1A80E525-2533-4598-8EB5-60A73D2F9253"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.4.4","matchCriteriaId":"E3A97142-27DF-46DD-9708-1CA202B7565C"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"10.0.3","matchCriteriaId":"595EBFC6-533E-4D91-B84D-D16A27E1BD0A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.4","matchCriteriaId":"EAC4A665-19CA-495D-A00F-6B42EA627E0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"10.0.3","matchCriteriaId":"705D34AF-DF94-4834-AE15-0E31E78AF60C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.648.205","matchCriteriaId":"2A4680B8-AC49-4E3C-8642-31BF8A60A327"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"},{"vulnerable":false,"criteria":"cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*","matchCriteriaId":"D32ACF6F-5FF7-4815-8EAD-4719F5FC9B79"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*","matchCriteriaId":"A01C8B7E-EB19-40EA-B1D2-9AE5EA536C95"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*","matchCriteriaId":"5646FDE9-CF21-46A9-B89D-F5BBDB4249AF"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*","matchCriteriaId":"DE554781-1EB9-446E-911F-6C11970C47F4"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*","matchCriteriaId":"4339DE06-19FB-4B8E-B6AE-3495F605AD05"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_desktop:11:sp1:*:*:*:*:*:*","matchCriteriaId":"60FBDD82-691C-4D9D-B71B-F9AFF6931B53"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"611","Ordinal":"1","Title":"CVE-2011-0611","CVE":"CVE-2011-0611","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"611","Ordinal":"1","NoteData":"Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a \"group of included constants,\" object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.","Type":"Description","Title":"CVE-2011-0611"},{"CveYear":"2011","CveId":"611","Ordinal":"2","NoteData":"2011-04-13","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"611","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}