CVE-2010-1284: Buffer Overflow
Published May 13, 2010
·Updated
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
Affected Software
46 affected components
Adobe Shockwave Player<=11.5.6.606
Adobe Shockwave Player=1.0
Adobe Shockwave Player=2.0
Adobe Shockwave Player=3.0
Adobe Shockwave Player=4.0
Adobe Shockwave Player=5.0
Adobe Shockwave Player=6.0
Adobe Shockwave Player=8.0
Adobe Shockwave Player=8.5.1
Adobe Shockwave Player=9
Adobe Shockwave Player=10.1.0.11
Adobe Shockwave Player=11.0.0.456
Adobe Shockwave Player=11.5.0.595
Adobe Shockwave Player=11.5.0.596
Adobe Shockwave Player=11.5.1.601
Adobe Shockwave Player=11.5.2.602
macOS
Microsoft Windows
Adobe Shockwave Player
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
All of the following
Any of the following
Adobe Shockwave Player<=11.5.6.606
Adobe Shockwave Player=1.0
Adobe Shockwave Player=2.0
Adobe Shockwave Player=3.0
Adobe Shockwave Player=4.0
Adobe Shockwave Player=5.0
Adobe Shockwave Player=6.0
Adobe Shockwave Player=8.0
Adobe Shockwave Player=8.5.1
Adobe Shockwave Player=9
Adobe Shockwave Player=10.1.0.11
Adobe Shockwave Player=11.0.0.456
Adobe Shockwave Player=11.5.0.595
Adobe Shockwave Player=11.5.0.596
Adobe Shockwave Player=11.5.1.601
Adobe Shockwave Player=11.5.2.602
Any of the following
macOS
Microsoft Windows
All of the following
Adobe Shockwave Player
Any of the following
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Remediation
Patch Available
Event History
May 13, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
09:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·09:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1284?
CVE-2010-1284 has a high severity rating as it allows attackers to cause denial of service or potentially execute arbitrary code.
2
How do I fix CVE-2010-1284?
To fix CVE-2010-1284, update Adobe Shockwave Player to version 11.5.7.609 or later.
3
What versions of Adobe Shockwave Player are affected by CVE-2010-1284?
CVE-2010-1284 affects all versions of Adobe Shockwave Player prior to 11.5.7.609.
4
What type of vulnerability is CVE-2010-1284?
CVE-2010-1284 is classified as a memory corruption vulnerability.
5
Can CVE-2010-1284 be exploited remotely?
Yes, CVE-2010-1284 can be exploited remotely by an attacker to cause a denial of service.