CVE-2010-0128

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/05/2010
Last modified:
11/04/2025

Description

Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:director:*:*:*:*:*:*:*:* 11.5.7.609 (excluding)
cpe:2.3:a:adobe:shockwave_player:*:*:*:*:*:*:*:* 11.5.6.606 (including)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*