4.3

CVE-2010-0187

Exploit

Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeAdobe Air Version <= 1.5.3.9120
AdobeAdobe Air Version1.0
AdobeAdobe Air Version1.1
AdobeAdobe Air Version1.5.1
AdobeAdobe Air Version1.5.2
AdobeAdobe Air Version1.5.3
AdobeFlash Player Version <= 10.0.42.34
AdobeFlash Player Version6.0.21.0
AdobeFlash Player Version6.0.79
AdobeFlash Player Version7.0
AdobeFlash Player Version7.0.1
AdobeFlash Player Version7.0.25
AdobeFlash Player Version7.0.63
AdobeFlash Player Version7.0.69.0
AdobeFlash Player Version7.0.70.0
AdobeFlash Player Version7.1
AdobeFlash Player Version7.1.1
AdobeFlash Player Version7.2
AdobeFlash Player Version8.0
AdobeFlash Player Version8.0.22.0
AdobeFlash Player Version8.0.24.0
AdobeFlash Player Version8.0.33.0
AdobeFlash Player Version8.0.34.0
AdobeFlash Player Version8.0.35.0
AdobeFlash Player Version8.0.39.0
AdobeFlash Player Version8.0.42.0
AdobeFlash Player Version9.0
AdobeFlash Player Version9.0.16
AdobeFlash Player Version9.0.18d60
AdobeFlash Player Version9.0.20
AdobeFlash Player Version9.0.20.0
AdobeFlash Player Version9.0.28.0
AdobeFlash Player Version9.0.31
AdobeFlash Player Version9.0.31.0
AdobeFlash Player Version9.0.45.0
AdobeFlash Player Version9.0.47.0
AdobeFlash Player Version9.0.48.0
AdobeFlash Player Version9.0.112.0
AdobeFlash Player Version9.0.114.0
AdobeFlash Player Version9.0.115.0
AdobeFlash Player Version9.0.124.0
AdobeFlash Player Version9.0.125.0
AdobeFlash Player Version9.0.151.0
AdobeFlash Player Version9.0.152.0
AdobeFlash Player Version9.0.159.0
AdobeFlash Player Version9.0.246.0
AdobeFlash Player Version9.0.260.0
AdobeFlash Player Version9.125.0
AdobeFlash Player Version10.0.12.10
AdobeFlash Player Version10.0.12.36
AdobeFlash Player Version10.0.15.3
AdobeFlash Player Version10.0.22.87
AdobeFlash Player Version10.0.32.18
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 41.66% 0.971
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.