VDB
CVE-2012-6270
CVE-2012-6270
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of a Shockwave Player 10.4.0.025 compatibility feature via a crafted HTML document that references Shockwave content with a certain compatibility parameter, related to a "downgrading" attack.
EPSS 3.32% · 87.5th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
3.32%
87.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| adobe | shockwave_player | 1.0, 2.0, 5.0 |
Timeline
- Dec 20, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- VU#546769 third-party-advisory
- VU#323161 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-6270 advisory