Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2010-1297 | First vendor Publication | 2010-06-08 |
| Vendor | Cve | Last vendor Modification | 2012-11-05 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 9.3 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1297 |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:7116 | |||
| Oval ID: | oval:org.mitre.oval:def:7116 | ||
| Title: | Adobe Flash Player, Acrobat Reader, and Acrobat 'authplay.dll' Remote Code Execution Vulnerability | ||
| Description: | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2010-1297 |
Version: | 17 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows 7 |
Product(s): | Adobe Flash Player Adobe Reader Adobe Acrobat |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
SAINT Exploits
| Description | Link |
|---|---|
| Adobe Reader authplay.dll newfunction Memory Corruption | More info here |
ExploitDB Exploits
| id | Description |
|---|---|
| 2010-09-25 | Adobe Flash Player "newfunction" Invalid Pointer Use |
| 2010-09-20 | Adobe Flash Player "newfunction" Invalid Pointer Use |
| 2010-09-01 | MOAUB #1 - Adobe Acrobat Reader and Flash Player |
| 2010-06-09 | 0day Exploit for Adobe Flash and Reader PoC (from the wild) |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 65141 | Adobe Multiple Products SWF Handling Arbitrary Code Execution |
Metasploit Database
| id | Description |
|---|---|
| 2010-06-04 | Adobe Flash Player "newfunction" Invalid Pointer Use |
| 2010-06-04 | Adobe Flash Player "newfunction" Invalid Pointer Use |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-06-11 17:25:11 |
|
| 2013-06-11 13:25:32 |
|
| 2013-06-10 13:25:27 |
|
| 2013-06-10 09:25:20 |
|
| 2013-06-08 05:26:38 |
|
| 2013-06-07 21:25:03 |
|
| 2013-06-06 13:25:55 |
|
| 2013-06-06 05:24:31 |
|
| 2013-06-04 17:26:02 |
|
| 2013-06-04 13:25:13 |
|
| 2013-06-03 21:27:40 |
|
| 2013-06-03 17:21:47 |
|
| 2013-06-03 13:26:03 |
|
| 2013-06-03 05:22:12 |
|
| 2013-05-31 21:26:00 |
|
| 2013-05-31 17:21:51 |
|
| 2013-05-30 17:24:45 |
|
| 2013-05-30 13:21:54 |
|
| 2013-05-10 23:21:56 |
|
| 2013-05-01 17:22:37 |
|
| 2013-05-01 13:28:05 |
|
| 2013-05-01 09:22:46 |
|
| 2013-05-01 05:38:31 |
|
| 2012-11-07 05:19:28 |
|

CVE-2010-1297
(Critical)









