CVE-2010-2874
Summary
| CVE | CVE-2010-2874 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-09-07 18:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption. NOTE: due to conflicting information and use of the same CVE identifier by the vendor, ZDI, and TippingPoint, it is not clear whether this issue is related to use of an uninitialized pointer, an incorrect pointer offset calculation, or both. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Shockwave Player | 1.0 | All | All | All |
| Application | Adobe | Shockwave Player | 10.0.0.210 | All | All | All |
| Application | Adobe | Shockwave Player | 10.0.1.004 | All | All | All |
| Application | Adobe | Shockwave Player | 10.1.0.011 | All | All | All |
| Application | Adobe | Shockwave Player | 10.1.0.11 | All | All | All |
| Application | Adobe | Shockwave Player | 10.1.1.016 | All | All | All |
| Application | Adobe | Shockwave Player | 10.1.4.020 | All | All | All |
| Application | Adobe | Shockwave Player | 10.2.0.021 | All | All | All |
| Application | Adobe | Shockwave Player | 10.2.0.022 | All | All | All |
| Application | Adobe | Shockwave Player | 10.2.0.023 | All | All | All |
| Application | Adobe | Shockwave Player | 11.0.0.456 | All | All | All |
| Application | Adobe | Shockwave Player | 11.0.3.471 | All | All | All |
| Application | Adobe | Shockwave Player | 11.5.0.595 | All | All | All |
| Application | Adobe | Shockwave Player | 11.5.0.596 | All | All | All |
| Application | Adobe | Shockwave Player | 11.5.1.601 | All | All | All |
| Application | Adobe | Shockwave Player | 11.5.2.602 | All | All | All |
| Application | Adobe | Shockwave Player | 11.5.6.606 | All | All | All |
| Application | Adobe | Shockwave Player | 2.0 | All | All | All |
| Application | Adobe | Shockwave Player | 3.0 | All | All | All |
| Application | Adobe | Shockwave Player | 4.0 | All | All | All |
| Application | Adobe | Shockwave Player | 5.0 | All | All | All |
| Application | Adobe | Shockwave Player | 6.0 | All | All | All |
| Application | Adobe | Shockwave Player | 8.0 | All | All | All |
| Application | Adobe | Shockwave Player | 8.0.196 | All | All | All |
| Application | Adobe | Shockwave Player | 8.0.196a | All | All | All |
| Application | Adobe | Shockwave Player | 8.0.204 | All | All | All |
| Application | Adobe | Shockwave Player | 8.0.205 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.1 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.1.100 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.1.103 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.1.105 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.1.106 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.321 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.323 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.324 | All | All | All |
| Application | Adobe | Shockwave Player | 8.5.325 | All | All | All |
| Application | Adobe | Shockwave Player | 9 | All | All | All |
| Application | Adobe | Shockwave Player | 9.0.383 | All | All | All |
| Application | Adobe | Shockwave Player | 9.0.432 | All | All | All |
| Application | Adobe | Shockwave Player | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Adobe - Security Bulletins: APSB10-20 - Security update available for Shockwave Player | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| SecurityTracker.com Archives - Adobe Shockwave Player Has Multiple Flaws That Let Remote Users Execute Arbitrary Code or Deny Service | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.