VulnerabilityModified
CVE-2010-4196
The Shockwave 3d Asset module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
HIGH 9.3EPSS 5.56%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Shockwave 3d Asset module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.56% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- adobe/shockwave player
- Source
- psirt@adobe.com
References
- http://www.adobe.com/support/security/bulletins/apsb11-01.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/189929US Government Resource
- http://www.securityfocus.com/bid/46338
- http://www.securitytracker.com/id?1025056
- http://www.vupen.com/english/advisories/2011/0335Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb11-01.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/189929US Government Resource
- http://www.securityfocus.com/bid/46338
- http://www.securitytracker.com/id?1025056
- http://www.vupen.com/english/advisories/2011/0335Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.