RETIRED: Adobe Shockwave Player APSB10-20 Multiple Remote Vulnerabilities

BID:42657

Info

RETIRED: Adobe Shockwave Player APSB10-20 Multiple Remote Vulnerabilities

Bugtraq ID: 42657
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Aug 24 2010 12:00AM
Updated: Sep 01 2010 06:35PM
Credit: Honggang Ren of Fortinet's FortiGuard Labs, TippingPoint FuzzBox as driven by Aaron Portnoy and Logan Brown, Rodrigo Rubira Branco of CheckPoint, an Anonymous Researcher through TippingPoint's Zero Day Initiative, Damian Put, an Anonymous Researcher report
Vulnerable: Adobe Shockwave Player 11.5.7 .609
Adobe Shockwave Player 11.5.6 .606
Adobe Shockwave Player 11.5.2 .606
Adobe Shockwave Player 11.5.2 .602
Adobe Shockwave Player 11.5.1 .601
Adobe Shockwave Player 11.5 .601
Adobe Shockwave Player 11.5 .600
Adobe Shockwave Player 11.5 .596
Not Vulnerable: Adobe Shockwave Player 11.5.8.612

Discussion

RETIRED: Adobe Shockwave Player APSB10-20 Multiple Remote Vulnerabilities

Adobe Shockwave Player is prone to multiple remote vulnerabilities.

Attackers can exploit these issues to crash the affected application and execute arbitrary code within the context of the affected application.

Adobe Shockwave Player 11.5.7.609 and prior are vulnerable.

This BID is being retired. The following individual records exist to better document the issues:

42664 Adobe Shockwave Player CVE-2010-2863 Remote Memory Corruption Vulnerability
42665 Adobe Shockwave Player tSAC Chunk Remote Memory Corruption Vulnerability
42666 Adobe Shockwave Player CVE-2010-2864 Remote Memory Corruption Vulnerability
42667 Adobe Shockwave Player Director File 0xFFFFFF45 RIFF Record Remote Memory Corruption Vulnerability
42668 Adobe Shockwave Player CVE-2010-2875 Remote Memory Corruption Vulnerability
42669 Adobe Shockwave Player TextXtra Allocator Integer Overflow Vulnerability
42670 Adobe Shockwave Player CVE-2010-2880 Remote Memory Corruption Vulnerability
42671 Adobe Shockwave Player CVE-2010-2881 Remote Memory Corruption Vulnerability
42672 Adobe Shockwave Player CVE-2010-2882 Remote Memory Corruption Vulnerability
42673 Adobe Shockwave Player CVE-2010-2865 Denial of Service Vulnerability
42674 Adobe Shockwave Player CVE-2010-2869 Remote Memory Corruption Vulnerability
42675 Adobe Shockwave Player Director mmap Trusted Chunk Size Remote Memory Corruption Vulnerability
42676 Adobe Shockwave Player CVE-2010-2868 Multiple Remote Code Execution Vulnerabilities
42677 Adobe Shockwave Player Director File FFFFFF88 Record Remote Memory Corruption Vulnerability
42678 Adobe Shockwave Player CSWV Chunk Memory Corruption Remote Code Execution Vulnerability
42679 Adobe Shockwave Player Director PAMI Chunk Remote Memory Corruption Vulnerability
42680 Adobe Shockwave Player rcsL Chunk Remote Memory Corruption Vulnerability
42682 Adobe Shockwave Player Director rcsL Chunk Remote Memory Corruption Vulnerability
42683 Adobe Shockwave Player 'DIRAPIX.dll' Remote Memory Corruption Vulnerability
42684 Adobe Shockwave Player 'DIRAPIX.dll' File Remote Memory Corruption Vulnerability

Exploit / POC

RETIRED: Adobe Shockwave Player APSB10-20 Multiple Remote Vulnerabilities

Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

RETIRED: Adobe Shockwave Player APSB10-20 Multiple Remote Vulnerabilities

Solution:
Updates are available. Please see the references for details.

References

RETIRED: Adobe Shockwave Player APSB10-20 Multiple Remote Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report