CVE-2010-3654
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 69.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 69.68% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- adobe/flash player · macromedia/flash player · adobe/acrobat · adobe/acrobat reader
- Source
- psirt@adobe.com
References
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe_flash1
- http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.htmlExploit
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00001.html
- http://secunia.com/advisories/41917Vendor Advisory
- http://secunia.com/advisories/42030
- http://secunia.com/advisories/42183
- http://secunia.com/advisories/42401
- http://secunia.com/advisories/42926
- http://secunia.com/advisories/43025
- http://secunia.com/advisories/43026
- http://security.gentoo.org/glsa/glsa-201101-08.xml
- http://security.gentoo.org/glsa/glsa-201101-09.xml
- http://securityreason.com/securityalert/8210
- http://support.apple.com/kb/HT4435
- http://www.adobe.com/support/security/advisories/apsa10-05.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-26.html
- http://www.adobe.com/support/security/bulletins/apsb10-28.html
- http://www.kb.cert.org/vuls/id/298081US Government Resource
- http://www.redhat.com/support/errata/RHSA-2010-0829.html
- http://www.redhat.com/support/errata/RHSA-2010-0834.html
- http://www.redhat.com/support/errata/RHSA-2010-0867.html
- http://www.redhat.com/support/errata/RHSA-2010-0934.html
- http://www.securityfocus.com/bid/44504
- http://www.securitytracker.com/id?1024659
- http://www.securitytracker.com/id?1024660
- http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txt
- http://www.vupen.com/english/advisories/2010/2903
- http://www.vupen.com/english/advisories/2010/2906
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.