CVE-2010-2172
published 2010-06-15CVE-2010-2172: Adobe Flash Player 9 before 9.0.277.0 on unspecified UNIX platforms allows attackers to cause a denial of service via unknown vectors.
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.96%
91.2th percentile
Adobe Flash Player 9 before 9.0.277.0 on unspecified UNIX platforms allows attackers to cause a denial of service via unknown vectors.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9v5r-66m6-3m5v: Adobe Flash Player 9 before 9
ghsa_unreviewed·2022-05-17
CVE-2010-2172 [MEDIUM] GHSA-9v5r-66m6-3m5v: Adobe Flash Player 9 before 9
Adobe Flash Player 9 before 9.0.277.0 on unspecified UNIX platforms allows attackers to cause a denial of service via unknown vectors.
Red Hat
flash-plugin: "possible player crash" affects also v9.x versions of Adobe Flash Player
vendor_redhat·2010-06-10·CVSS 4.3
CVE-2010-2172 [MEDIUM] flash-plugin: "possible player crash" affects also v9.x versions of Adobe Flash Player
flash-plugin: "possible player crash" affects also v9.x versions of Adobe Flash Player
Adobe Flash Player 9 before 9.0.277.0 on unspecified UNIX platforms allows attackers to cause a denial of service via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
flash-plugin: multiple security flaws (APSB10-14)
bugzilla·2010-06-10·CVSS 9.3
CVE-2010-1297 [CRITICAL] flash-plugin: multiple security flaws (APSB10-14)
flash-plugin: multiple security flaws (APSB10-14)
Today, 2010-06-10, Adobe is planning to release an update
for Adobe Flash Player of version 10.0.45.2 (new version
is 10.1.53.64), to address multiple security issues allowing
code execution, whose description is detailed in the Adobe
Security Bulletin APSB10-14:
[1] http://www.adobe.com/support/security/bulletins/apsb10-14.html
* This update resolves a memory corruption vulnerability that could lead
to code execution (CVE-2010-1297). Note: There are reports that this
issue is being actively exploited in the wild.
* This update resolves a memory exhaustion vulnerability that could lead
to code execution (CVE-2009-3793).
* This update resolves a memory corruption vulnerability that could lead
to code execution (CVE-2010-2160).
* This u
Bugzilla
CVE-2010-2172 flash-plugin: CVE-2010-0187 "possible player crash" affects also v9.x versions of Adobe Flash Player
bugzilla·2010-06-10·CVSS 4.3
CVE-2010-2172 [MEDIUM] CVE-2010-2172 flash-plugin: CVE-2010-0187 "possible player crash" affects also v9.x versions of Adobe Flash Player
CVE-2010-2172 flash-plugin: CVE-2010-0187 "possible player crash" affects also v9.x versions of Adobe Flash Player
Originally, the following CVE-2010-0187 security flaw has been reported
against Adobe Flash Player v10.x and earlier versions:
[1] http://www.adobe.com/support/security/bulletins/apsb10-06.html
CVE-2010-0187 got following description from MITRE:
"Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow
remote attackers to cause a denial of service (application crash) via a
modified SWF file."
Public reproducers for the CVE-2010-0187 are available here:
[2] http://www.exploit-db.com/exploits/11182/
[3] http://sebug.net/exploit/18967/
Further testing showed, this deficiency affects also v9.x based versions
of Adobe Flash Player. This new discovered flaw go
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/40545http://secunia.com/advisories/43026http://security.gentoo.org/glsa/glsa-201101-09.xmlhttp://securitytracker.com/id?1024085http://support.apple.com/kb/HT4435http://www.adobe.com/support/security/bulletins/apsb10-14.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0470.htmlhttp://www.securityfocus.com/bid/40759http://www.securityfocus.com/bid/40795http://www.turbolinux.co.jp/security/2010/TLSA-2010-19j.txthttp://www.us-cert.gov/cas/techalerts/TA10-162A.htmlhttp://www.vupen.com/english/advisories/2010/1421http://www.vupen.com/english/advisories/2010/1434http://www.vupen.com/english/advisories/2010/1453http://www.vupen.com/english/advisories/2010/1482http://www.vupen.com/english/advisories/2010/1522http://www.vupen.com/english/advisories/2010/1793http://www.vupen.com/english/advisories/2011/0192https://exchange.xforce.ibmcloud.com/vulnerabilities/59322https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14072http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/40545http://secunia.com/advisories/43026http://security.gentoo.org/glsa/glsa-201101-09.xmlhttp://securitytracker.com/id?1024085http://support.apple.com/kb/HT4435http://www.adobe.com/support/security/bulletins/apsb10-14.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0470.htmlhttp://www.securityfocus.com/bid/40759http://www.securityfocus.com/bid/40795http://www.turbolinux.co.jp/security/2010/TLSA-2010-19j.txthttp://www.us-cert.gov/cas/techalerts/TA10-162A.htmlhttp://www.vupen.com/english/advisories/2010/1421http://www.vupen.com/english/advisories/2010/1434http://www.vupen.com/english/advisories/2010/1453http://www.vupen.com/english/advisories/2010/1482http://www.vupen.com/english/advisories/2010/1522http://www.vupen.com/english/advisories/2010/1793http://www.vupen.com/english/advisories/2011/0192https://exchange.xforce.ibmcloud.com/vulnerabilities/59322https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14072
2010-06-15
Published