Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-2874


Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption. NOTE: due to conflicting information and use of the same CVE identifier by the vendor, ZDI, and TippingPoint, it is not clear whether this issue is related to use of an uninitialized pointer, an incorrect pointer offset calculation, or both.


Published

2010-09-07T18:00:02.247

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe shockwave_player ≤ 11.5.7.609 Yes
Application adobe shockwave_player 1.0 Yes
Application adobe shockwave_player 2.0 Yes
Application adobe shockwave_player 3.0 Yes
Application adobe shockwave_player 4.0 Yes
Application adobe shockwave_player 5.0 Yes
Application adobe shockwave_player 6.0 Yes
Application adobe shockwave_player 8.0 Yes
Application adobe shockwave_player 8.0.196 Yes
Application adobe shockwave_player 8.0.196a Yes
Application adobe shockwave_player 8.0.204 Yes
Application adobe shockwave_player 8.0.205 Yes
Application adobe shockwave_player 8.5.1 Yes
Application adobe shockwave_player 8.5.1.100 Yes
Application adobe shockwave_player 8.5.1.103 Yes
Application adobe shockwave_player 8.5.1.105 Yes
Application adobe shockwave_player 8.5.1.106 Yes
Application adobe shockwave_player 8.5.321 Yes
Application adobe shockwave_player 8.5.323 Yes
Application adobe shockwave_player 8.5.324 Yes
Application adobe shockwave_player 8.5.325 Yes
Application adobe shockwave_player 9 Yes
Application adobe shockwave_player 9.0.383 Yes
Application adobe shockwave_player 9.0.432 Yes
Application adobe shockwave_player 10.0.0.210 Yes
Application adobe shockwave_player 10.0.1.004 Yes
Application adobe shockwave_player 10.1.0.11 Yes
Application adobe shockwave_player 10.1.0.011 Yes
Application adobe shockwave_player 10.1.1.016 Yes
Application adobe shockwave_player 10.1.4.020 Yes
Application adobe shockwave_player 10.2.0.021 Yes
Application adobe shockwave_player 10.2.0.022 Yes
Application adobe shockwave_player 10.2.0.023 Yes
Application adobe shockwave_player 11.0.0.456 Yes
Application adobe shockwave_player 11.0.3.471 Yes
Application adobe shockwave_player 11.5.0.595 Yes
Application adobe shockwave_player 11.5.0.596 Yes
Application adobe shockwave_player 11.5.1.601 Yes
Application adobe shockwave_player 11.5.2.602 Yes
Application adobe shockwave_player 11.5.6.606 Yes

References