CVE-2010-1297
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product is end-of-life and should be disconnected if still in use.
Added 2022-06-08Remediation due 2022-06-22
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
7.8
CVSS
82.2%
EPSS (exploit prob.)
100th
EPSS percentile
2010-06-08
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | air | < 2.0.2.12610 |
| adobe | flash_player | < 9.0.277.0 |
| adobe | flash_player | >= 10.0, < 10.1.53.64 |
| adobe | acrobat | >= 8.0, < 8.2.3 |
| adobe | acrobat | >= 9.0, < 9.3.3 |
| apple | mac_os_x | all versions |
| microsoft | windows | all versions |
| opensuse | opensuse | >= 11.0, <= 11.2 |
| suse | linux_enterprise | 10.0 |
| suse | linux_enterprise | 11.0 |
| suse | linux_enterprise | 11.0 |
Check a specific version with /api/v1/cve/match.
References
- http://blog.zynamics.com/2010/06/09/analyzing-the-currently-exploited-0-day-for-adobe-reader-and-adobe-flash/
- http://community.websense.com/blogs/securitylabs/archive/2010/06/09/having-fun-with-adobe-0-day-exploits.aspx
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- http://secunia.com/advisories/40026
- http://secunia.com/advisories/40034
- http://secunia.com/advisories/40144
- http://secunia.com/advisories/40545
- http://secunia.com/advisories/43026
- http://security.gentoo.org/glsa/glsa-201101-09.xml
- http://securitytracker.com/id?1024057
- http://securitytracker.com/id?1024058
- http://securitytracker.com/id?1024085
- http://securitytracker.com/id?1024086
- http://support.apple.com/kb/HT4435
- http://www.adobe.com/support/security/advisories/apsa10-01.html
- http://www.adobe.com/support/security/bulletins/apsb10-14.html
- http://www.adobe.com/support/security/bulletins/apsb10-15.html
- http://www.exploit-db.com/exploits/13787
- http://www.kb.cert.org/vuls/id/486225
- http://www.osvdb.org/65141
- http://www.redhat.com/support/errata/RHSA-2010-0464.html
- http://www.redhat.com/support/errata/RHSA-2010-0470.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-1297