CVE-2010-2874 Information

Description

Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption. NOTE: due to conflicting information and use of the same CVE identifier by the vendor ZDI and TippingPoint it is not clear whether this issue is related to use of an uninitialized pointer an incorrect pointer offset calculation or both.

Reference

http://www.adobe.com/support/security/bulletins/apsb10-20.html http://www.securitytracker.com/id?1024361 http://www.vupen.com/english/advisories/2010/2176 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A11924

Share on: