CVE-2010-1297
Description
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Out-of-bounds Write
DraftCommon Consequences
Applicable Platforms
Adobe Flash / Reader - Live Malware
VerifiedAdobe Flash / Reader - Live Malware
View Exploit Code →Adobe Acrobat Reader and Flash Player - 'newclass' …
VerifiedAdobe Acrobat Reader and Flash Player - 'newclass' Invalid Pointer
View Exploit Code →Adobe Flash Player - 'newfunction' Invalid Pointer Use …
Verified Metasploit Framework (MSF)Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (1)
View Exploit Code →Adobe Flash Player - 'newfunction' Invalid Pointer Use …
Verified Metasploit Framework (MSF)Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2)
View Exploit Code →Linux Enterprise by Suse
cpe:2.3:o:suse:linux_enterprise:10.0:sp3:*:*:*:*:*:*
Linux Enterprise by Suse
cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*
Flash Player by Adobe
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
Flash Player by Adobe
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
Acrobat by Adobe
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Linux Enterprise by Suse
cpe:2.3:o:suse:linux_enterprise:11.0:sp1:*:*:*:*:*:*
Acrobat by Adobe
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
Opensuse by Opensuse
cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*
Air by Adobe
cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*