CVE-2010-1297

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 8, 2010
Updated: Jan 6, 2025
CWE ID 787

Summary

CVE-2010-1297 is a critical vulnerability affecting Adobe Flash Player versions before 9.0.277.0 and 10.x before 10.1.53.64, Adobe AIR before 2.0.2.12610, Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X. This issue allows remote attackers to execute arbitrary code or cause a denial of service by exploiting a memory corruption vulnerability in authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction. The vulnerability was exploited in the wild in June 2010, making it a significant threat to users of the affected software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Flash Player
  • Adobe Reader XI
  • Adobe AIR
  • Adobe Acrobat
  • Open SUSE

Affected Vendors

  • Adobe
  • Opensuse
  • SUSE Linux GmbH