CVE-2010-3654 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 69.7% (pctl 99)
Patch early
A public exploit exists.
Description
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 69.68% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-10-29 |
| Last modified | 2026-06-16 |
Affected (9)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat reader |
| adobe | flash player |
| apple | mac os x |
| android | |
| linux | linux kernel |
| macromedia | flash player |
| microsoft | windows |
| oracle | solaris |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash Player < 10.1.53.64 - Action Script Type Confusion (ASLR + DEP Bypass) | 2011-04-19 |
| exploit-db | Adobe Flash Player - 'Button' Arbitrary Code Execution (Metasploit) | 2010-11-01 |
References
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe_flash1
- http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00001.html
- http://secunia.com/advisories/41917
- http://secunia.com/advisories/42030
- http://secunia.com/advisories/42183
- http://secunia.com/advisories/42401
- http://secunia.com/advisories/42926
- http://secunia.com/advisories/43025
- http://secunia.com/advisories/43026
- http://security.gentoo.org/glsa/glsa-201101-08.xml
- http://security.gentoo.org/glsa/glsa-201101-09.xml
- http://securityreason.com/securityalert/8210
- http://support.apple.com/kb/HT4435
- http://www.adobe.com/support/security/advisories/apsa10-05.html
- http://www.adobe.com/support/security/bulletins/apsb10-26.html
- http://www.adobe.com/support/security/bulletins/apsb10-28.html
- http://www.kb.cert.org/vuls/id/298081
→ the Explorer · watch your stack · NVD