{"api_version":"1","generated_at":"2026-07-23T09:09:05+00:00","cve":"CVE-2012-5277","urls":{"html":"https://cve.report/CVE-2012-5277","api":"https://cve.report/api/cve/CVE-2012-5277.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-5277","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-5277"},"summary":{"title":"CVE-2012-5277","description":"Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5280.","state":"PUBLISHED","assigner":"adobe","published_at":"2012-11-07 05:41:22","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/51245","name":"http://secunia.com/advisories/51245","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA51245 - SUSE update for flash-player - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51213","name":"http://secunia.com/advisories/51213","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00030.html","name":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00030.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2013:0367-1: important: flash-player: Up","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.adobe.com/support/security/bulletins/apsb12-24.html","name":"http://www.adobe.com/support/security/bulletins/apsb12-24.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe - Security Bulletins: APSB12-24 - Security updates available for Adobe Flash Player","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79848","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79848","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51186","name":"http://secunia.com/advisories/51186","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA51186 - Red Hat update flash-plugin - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1027730","name":"http://www.securitytracker.com/id?1027730","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Adobe Flash Player Buffer Overflows and Memory Corruption Errors Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-1431.html","name":"http://rhn.redhat.com/errata/RHSA-2012-1431.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00007.html","name":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2012:1485-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00012.html","name":"http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00012.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2013:0134-1: important: Update to 11.2.2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00005.html","name":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2012:1480-1: important: flash-player: Up","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51207","name":"http://secunia.com/advisories/51207","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-5277","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5277","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"5277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T20:58:03.534Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"openSUSE-SU-2013:0134","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00012.html"},{"name":"RHSA-2012:1431","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1431.html"},{"name":"51245","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51245"},{"name":"adobe-cve20125277-bo(79848)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79848"},{"name":"1027730","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1027730"},{"name":"openSUSE-SU-2013:0367","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00030.html"},{"name":"51186","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51186"},{"name":"openSUSE-SU-2012:1480","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00005.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb12-24.html"},{"name":"SUSE-SU-2012:1485","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00007.html"},{"name":"51213","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51213"},{"name":"51207","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51207"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-11-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5280."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"name":"openSUSE-SU-2013:0134","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00012.html"},{"name":"RHSA-2012:1431","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1431.html"},{"name":"51245","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51245"},{"name":"adobe-cve20125277-bo(79848)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79848"},{"name":"1027730","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1027730"},{"name":"openSUSE-SU-2013:0367","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00030.html"},{"name":"51186","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51186"},{"name":"openSUSE-SU-2012:1480","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00005.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb12-24.html"},{"name":"SUSE-SU-2012:1485","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00007.html"},{"name":"51213","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51213"},{"name":"51207","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51207"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2012-5277","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5280."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"openSUSE-SU-2013:0134","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00012.html"},{"name":"RHSA-2012:1431","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2012-1431.html"},{"name":"51245","refsource":"SECUNIA","url":"http://secunia.com/advisories/51245"},{"name":"adobe-cve20125277-bo(79848)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79848"},{"name":"1027730","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1027730"},{"name":"openSUSE-SU-2013:0367","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00030.html"},{"name":"51186","refsource":"SECUNIA","url":"http://secunia.com/advisories/51186"},{"name":"openSUSE-SU-2012:1480","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00005.html"},{"name":"http://www.adobe.com/support/security/bulletins/apsb12-24.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb12-24.html"},{"name":"SUSE-SU-2012:1485","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00007.html"},{"name":"51213","refsource":"SECUNIA","url":"http://secunia.com/advisories/51213"},{"name":"51207","refsource":"SECUNIA","url":"http://secunia.com/advisories/51207"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2012-5277","datePublished":"2012-11-07T02:00:00.000Z","dateReserved":"2012-10-04T00:00:00.000Z","dateUpdated":"2024-08-06T20:58:03.534Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-11-07 05:41:22","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"10.3","versionEndExcluding":"10.3.183.43","matchCriteriaId":"84D3ADD1-22BB-4171-B52C-44643F20C325"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"11.4","versionEndExcluding":"11.5.502.110","matchCriteriaId":"F7B14205-C8B9-4895-BB52-220A5BB0DAC3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"10.3","versionEndExcluding":"10.3.183.43","matchCriteriaId":"84D3ADD1-22BB-4171-B52C-44643F20C325"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"11.2","versionEndExcluding":"11.2.202.251","matchCriteriaId":"987B9258-49FB-4EEA-A743-47DC41A084F4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"11.1","versionEndExcluding":"11.1.111.24","matchCriteriaId":"F2CB54C5-19C3-4576-B71A-8E7FC319E871"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0","versionEndIncluding":"2.3.7","matchCriteriaId":"1F3C0381-865A-4176-A291-988E12612161"},{"vulnerable":false,"criteria":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndIncluding":"3.2.6","matchCriteriaId":"EBEB1CC1-D410-4157-8BF3-8EB8BAC444DD"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"11.1","versionEndExcluding":"11.1.115.27","matchCriteriaId":"57A71597-4B26-4AF8-9629-E89BC2BFD44C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndIncluding":"4.4.4","matchCriteriaId":"539FC1E0-6987-48EE-8FE9-7A27D4C3B69A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*","versionEndExcluding":"3.5.0.600","matchCriteriaId":"A4DF0527-B116-4896-B009-C99E4EE57D58"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.5.0.600","matchCriteriaId":"D32F4AA6-9FA6-4823-896A-A4B9140AD70B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"5277","Ordinal":"1","Title":"CVE-2012-5277","CVE":"CVE-2012-5277","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"5277","Ordinal":"1","NoteData":"Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5280.","Type":"Description","Title":"CVE-2012-5277"},{"CveYear":"2012","CveId":"5277","Ordinal":"2","NoteData":"2012-11-06","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"5277","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}