CVE-2010-1297

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
08/06/2010
Last modified:
22/10/2025

Description

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* 2.0.2.12610 (excluding)
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 9.0.277.0 (excluding)
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* 10.0 (including) 10.1.53.64 (excluding)
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* 8.0 (including) 8.2.3 (excluding)
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* 9.0 (including) 9.3.3 (excluding)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:* 11.0 (including) 11.2 (including)
cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:11.0:sp1:*:*:*:*:*:*


References to Advisories, Solutions, and Tools