CVE-2010-2215
published 2010-08-11CVE-2010-2215: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2)…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.85%
88.9th percentile
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "click-jacking" issue.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | flash_player | <= 10.1.53.64 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple security flaws (APSB10-16)
vendor_redhat·2010-08-10·CVSS 4.3
CVE-2010-2215 [MEDIUM] flash-plugin: multiple security flaws (APSB10-16)
flash-plugin: multiple security flaws (APSB10-16)
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "click-jacking" issue.
GHSA
GHSA-5rh8-5qgm-3qcp: Adobe Flash Player before 9
ghsa_unreviewed·2022-05-14
CVE-2010-2215 [MEDIUM] GHSA-5rh8-5qgm-3qcp: Adobe Flash Player before 9
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "click-jacking" issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0209 CVE-2010-2213 CVE-2010-2214 CVE-2010-2215 CVE-2010-2216 flash-plugin: multiple security flaws (APSB10-16)
bugzilla·2010-08-10·CVSS 9.3
CVE-2010-0209 [CRITICAL] CVE-2010-0209 CVE-2010-2213 CVE-2010-2214 CVE-2010-2215 CVE-2010-2216 flash-plugin: multiple security flaws (APSB10-16)
CVE-2010-0209 CVE-2010-2213 CVE-2010-2214 CVE-2010-2215 CVE-2010-2216 flash-plugin: multiple security flaws (APSB10-16)
On 2010-08-10 Adobe plans to release an update for Adobe Flash Player, providing 10.1.82.76 and 9.0.280, to address multiple security issues allowing code execution. The flaws are described in the Adobe Security Bulletin APSB10-16:
http://www.adobe.com/support/security/bulletins/apsb10-16.html
* This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-0209).
* This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2188).
* This update resolves multiple memory corruption vulnerabilities that could lead to code execution (CVE-2010-2213).
* This update resolves a memory corruption vul
Bugzilla
CVE-2010-2597 libtiff: use of uninitialized values crash
bugzilla·2010-07-02·CVSS 4.3
CVE-2010-2597 [MEDIUM] CVE-2010-2597 libtiff: use of uninitialized values crash
CVE-2010-2597 libtiff: use of uninitialized values crash
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2597 to
the following vulnerability:
The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2
makes incorrect calls to the TIFFGetField function, which allows
remote attackers to cause a denial of service (application crash) via
a crafted TIFF image, related to "downsampled OJPEG input" and
possibly related to a compiler optimization that triggers a
divide-by-zero error.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2597
[2] http://bugzilla.maptools.org/show_bug.cgi?id=2215
[3] https://bugs.launchpad.net/bugs/593067
[4] https://bugzilla.redhat.com/show_bug.cgi?id=583081
[5] https://bugzilla.redhat.com/show_bug.cgi?id=603703
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=128767780602751&w=2http://secunia.com/advisories/43026http://security.gentoo.org/glsa/glsa-201101-09.xmlhttp://support.apple.com/kb/HT4435http://www.adobe.com/support/security/bulletins/apsb10-16.htmlhttp://www.securityfocus.com/bid/42361http://www.securitytracker.com/id?1024621http://www.vupen.com/english/advisories/2011/0192https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11532https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16192http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=128767780602751&w=2http://secunia.com/advisories/43026http://security.gentoo.org/glsa/glsa-201101-09.xmlhttp://support.apple.com/kb/HT4435http://www.adobe.com/support/security/bulletins/apsb10-16.htmlhttp://www.securityfocus.com/bid/42361http://www.securitytracker.com/id?1024621http://www.vupen.com/english/advisories/2011/0192https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11532https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16192
2010-08-11
Published