peter bassill · operator
$ cve CVE-2010-3654 JSON

CVE-2010-3654 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 69.7% (pctl 99)

Patch early

A public exploit exists.

Description

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS69.68% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2010-10-29
Last modified2026-06-16

Affected (9)

VendorProduct
adobeacrobat
adobeacrobat reader
adobeflash player
applemac os x
googleandroid
linuxlinux kernel
macromediaflash player
microsoftwindows
oraclesolaris

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD