← All CVEs

CVE-2010-3653

high · 9.3

The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value is used as a pointer offset, as exploited in the wild in October 2010. NOTE: some of these details are obtained from third party information.

9.3
CVSS
74.6%
EPSS (exploit prob.)
99th
EPSS percentile
2010-10-26
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
adobeshockwave_player<= 11.5.8.612
adobeshockwave_player1.0
adobeshockwave_player2.0
adobeshockwave_player3.0
adobeshockwave_player4.0
adobeshockwave_player5.0
adobeshockwave_player6.0
adobeshockwave_player8.0
adobeshockwave_player8.0.196
adobeshockwave_player8.0.196a
adobeshockwave_player8.0.204
adobeshockwave_player8.0.205
adobeshockwave_player8.5.1
adobeshockwave_player8.5.1.100
adobeshockwave_player8.5.1.103
adobeshockwave_player8.5.1.105
adobeshockwave_player8.5.1.106
adobeshockwave_player8.5.321
adobeshockwave_player8.5.323
adobeshockwave_player8.5.324
adobeshockwave_player8.5.325
adobeshockwave_player9.0.383
adobeshockwave_player9.0.432
adobeshockwave_player10.0.0.210
adobeshockwave_player10.0.1.004
adobeshockwave_player10.1.0.11
adobeshockwave_player10.1.0.011
adobeshockwave_player10.1.1.016
adobeshockwave_player10.1.4.020
adobeshockwave_player10.2.0.021
adobeshockwave_player10.2.0.022
adobeshockwave_player10.2.0.023
adobeshockwave_player11.0.0.456
adobeshockwave_player11.0.3.471
adobeshockwave_player11.5.0.595
adobeshockwave_player11.5.0.596
adobeshockwave_player11.5.1.601
adobeshockwave_player11.5.2.602
adobeshockwave_player11.5.6.606
adobeshockwave_player11.5.7.609

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-3653