CVE-2010-0378
published 2010-01-21CVE-2010-0378: Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.23%
92.7th percentile
Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accessed by a script, leading to memory corruption, aka a "Movie Unloading Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mw25-vxhh-vf58: Multiple unspecified vulnerabilities in the Macromedia Flash ActiveX control in Adobe Flash Player 6, as distributed in Microsoft Windows XP SP2 and S
ghsa_unreviewed·2022-05-02·CVSS 8.8
CVE-2010-0379 [HIGH] GHSA-mw25-vxhh-vf58: Multiple unspecified vulnerabilities in the Macromedia Flash ActiveX control in Adobe Flash Player 6, as distributed in Microsoft Windows XP SP2 and S
Multiple unspecified vulnerabilities in the Macromedia Flash ActiveX control in Adobe Flash Player 6, as distributed in Microsoft Windows XP SP2 and SP3, might allow remote attackers to execute arbitrary code via unspecified vectors that are not related to the use-after-free "Movie Unloading Vulnerability" (CVE-2010-0378). NOTE: due to lack of details, it is not clear whether this overlaps any other CVE item.
GHSA
GHSA-r859-p3hv-36hf: Use-after-free vulnerability in Adobe Flash Player 6
ghsa_unreviewed·2022-05-02
CVE-2010-0378 [HIGH] CWE-416 GHSA-r859-p3hv-36hf: Use-after-free vulnerability in Adobe Flash Player 6
Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accessed by a script, leading to memory corruption, aka a "Movie Unloading Vulnerability."
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/27105http://secunia.com/secunia_research/2007-77/http://securitytracker.com/id?1023435http://www.kb.cert.org/vuls/id/204889http://www.microsoft.com/technet/security/advisory/979267.mspxhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7580http://secunia.com/advisories/27105http://secunia.com/secunia_research/2007-77/http://securitytracker.com/id?1023435http://www.kb.cert.org/vuls/id/204889http://www.microsoft.com/technet/security/advisory/979267.mspxhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7580
2010-01-21
Published