CVE-2010-0986

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/05/2010
Last modified:
11/04/2025

Description

Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:shockwave_player:*:*:*:*:*:*:*:* 11.5.7.609 (excluding)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*