CVE-2010-1297
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Flash Player Memory Corruption Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 82% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-787
מוצרים מושפעים
adobe: air; adobe: flash player; adobe: acrobat; apple: mac os x; microsoft: windows; opensuse: opensuse; suse: linux enterprise
קישורים
- http://secunia.com/advisories/40026 Broken LinkVendor Advisory
- http://secunia.com/advisories/40034 Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa10-01.html Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1348 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/1349 Broken LinkVendor Advisory
- http://secunia.com/advisories/40026 Broken LinkVendor Advisory
- http://secunia.com/advisories/40034 Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa10-01.html Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1348 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/1349 Broken LinkVendor Advisory