flash-plugin: crash and potential arbitrary code execution (APSB11-12)
Published May 13, 2011
8.8
HIGHCVSS 3.1
EPSS 5.11%
Description
Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
Affected products
No data.
Configuration 1
- ≤ 10.2.159.1
- 6.0.21.0
- 6.0.79
- 7.0
- 7.0.1
- 7.0.14.0
- 7.0.19.0
- 7.0.24.0
- 7.0.25
- 7.0.53.0
- 7.0.60.0
- 7.0.61.0
- 7.0.63
- 7.0.66.0
- 7.0.67.0
- 7.0.68.0
- 7.0.69.0
- 7.0.70.0
- 7.0.73.0
- 7.1
- 7.1.1
- 7.2
- 8.0
- 8.0.22.0
- 8.0.24.0
- 8.0.33.0
- 8.0.34.0
- 8.0.35.0
- 8.0.39.0
- 8.0.42.0
- 9.0
- 9.0.16
- 9.0.18d60
- 9.0.20
- 9.0.20.0
- 9.0.28
- 9.0.28.0
- 9.0.31
- 9.0.31.0
- 9.0.45.0
- 9.0.47.0
- 9.0.48.0
- 9.0.112.0
- 9.0.114.0
- 9.0.115.0
- 9.0.124.0
- 9.0.125.0
- 9.0.151.0
- 9.0.152.0
- 9.0.155.0
- 9.0.159.0
- 9.0.246.0
- 9.0.260.0
- 9.0.262.0
- 9.0.277.0
- 9.0.283.0
- 9.125.0
- 10.0.0.584
- 10.0.12.10
- 10.0.12.36
- 10.0.15.3
- 10.0.22.87
- 10.0.32.18
- 10.0.42.34
- 10.0.45.2
- 10.1.52.14.1
- 10.1.52.15
- 10.1.53.64
- 10.1.82.76
- 10.1.85.3
- 10.1.92.8
- 10.1.92.10
- 10.1.95.1
- 10.1.95.2
- 10.1.102.64
- 10.2.152
- 10.2.152.32
- 10.2.152.33
- 10.2.154.13
- 10.2.154.25
Configuration 2
- ≤ 10.2.157.51
- 10.1.92.8
- 10.1.92.10
- 10.1.95.2
- 10.1.105.6
- 10.1.106.16
- 10.2.156.12
No data.
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:10.3.181.14-1.el6
Fixed · RHSA-2011:0511
Supplementary for Red Hat Enterprise Linux 5
flash-plugin-0:10.3.181.14-1.el5
Fixed · RHSA-2011:0511
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:10.3.181.14-1.el6 | Fixed | RHSA-2011:0511 |
| Supplementary for Red Hat Enterprise Linux 5 | flash-plugin-0:10.3.181.14-1.el5 | Fixed | RHSA-2011:0511 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 23, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.11% (0.05107) | 92.11th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.53% (0.04527) | 90.29th | v5 (v2026.06.15) |
| Jun 17, 2025 | 7.86% (0.07860) | 91.53th | v4 (v2025.03.14) |
| Mar 30, 2025 | 9.97% (0.09971) | 92.30th | v4 (v2025.03.14) |
| Mar 29, 2025 | 14.30% (0.14302) | 90.69th | v4 (v2025.03.14) |
| Mar 17, 2025 | 9.97% (0.09971) | 92.46th | v4 (v2025.03.14) |
| Dec 17, 2024 | 3.11% (0.03112) | 90.85th | v3 (v2023.03.01) |
| Dec 12, 2024 | 4.86% (0.04863) | 93.06th | v3 (v2023.03.01) |
| Feb 20, 2024 | 4.12% (0.04117) | 91.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.22% (0.03218) | 89.68th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.00% (0.06995) | 92.22th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.00% (0.06995) | 91.48th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.00% (0.06995) | 79.96th | v2 (v2022.01.01) |
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00006.html vendor-advisoryx_refsource_SUSE
- http://www.adobe.com/support/security/bulletins/apsb11-12.html x_refsource_CONFIRMPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2011-0627 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=704368 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2011-0627
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13914 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16053 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2011-0627
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00006.html | vendor-advisoryx_refsource_SUSE | |
| http://www.adobe.com/support/security/bulletins/apsb11-12.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2011-0627 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=704368 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2011-0627 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13914 | vdb-entrysignaturex_refsource_OVAL | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16053 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2011-0627 |
Change history (0)
No recorded changes yet.