CVE-2010-2216
published 2010-08-11CVE-2010-2216: Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.59%
90.6th percentile
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | flash_player | <= 10.1.53.64 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89mr-5p7g-mp6c: Adobe Flash Player before 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2213 [CRITICAL] CWE-94 GHSA-89mr-5p7g-mp6c: Adobe Flash Player before 9
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2214, and CVE-2010-2216.
GHSA
GHSA-fhc9-8cx6-h467: Adobe Flash Player before 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2214 [CRITICAL] CWE-94 GHSA-fhc9-8cx6-h467: Adobe Flash Player before 9
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2216.
GHSA
GHSA-248p-gq7w-24rp: Adobe Flash Player before 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2216 [CRITICAL] CWE-94 GHSA-248p-gq7w-24rp: Adobe Flash Player before 9
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.
GHSA
GHSA-cc4q-35f8-jwmg: Adobe Flash Player before 9
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0209 [CRITICAL] CWE-94 GHSA-cc4q-35f8-jwmg: Adobe Flash Player before 9
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.
Red Hat
flash-plugin: multiple security flaws (APSB10-16)
vendor_redhat·2010-08-10·CVSS 9.3
CVE-2010-0209 [CRITICAL] flash-plugin: multiple security flaws (APSB10-16)
flash-plugin: multiple security flaws (APSB10-16)
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.
Red Hat
flash-plugin: multiple security flaws (APSB10-16)
vendor_redhat·2010-08-10·CVSS 9.3
CVE-2010-2216 [CRITICAL] flash-plugin: multiple security flaws (APSB10-16)
flash-plugin: multiple security flaws (APSB10-16)
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.
Red Hat
flash-plugin: multiple security flaws (APSB10-16)
vendor_redhat·2010-08-10·CVSS 9.3
CVE-2010-2213 [CRITICAL] flash-plugin: multiple security flaws (APSB10-16)
flash-plugin: multiple security flaws (APSB10-16)
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2214, and CVE-2010-2216.
Red Hat
flash-plugin: multiple security flaws (APSB10-16)
vendor_redhat·2010-08-10·CVSS 9.3
CVE-2010-2214 [CRITICAL] flash-plugin: multiple security flaws (APSB10-16)
flash-plugin: multiple security flaws (APSB10-16)
Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2216.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0209 CVE-2010-2213 CVE-2010-2214 CVE-2010-2215 CVE-2010-2216 flash-plugin: multiple security flaws (APSB10-16)
bugzilla·2010-08-10·CVSS 9.3
CVE-2010-0209 [CRITICAL] CVE-2010-0209 CVE-2010-2213 CVE-2010-2214 CVE-2010-2215 CVE-2010-2216 flash-plugin: multiple security flaws (APSB10-16)
CVE-2010-0209 CVE-2010-2213 CVE-2010-2214 CVE-2010-2215 CVE-2010-2216 flash-plugin: multiple security flaws (APSB10-16)
On 2010-08-10 Adobe plans to release an update for Adobe Flash Player, providing 10.1.82.76 and 9.0.280, to address multiple security issues allowing code execution. The flaws are described in the Adobe Security Bulletin APSB10-16:
http://www.adobe.com/support/security/bulletins/apsb10-16.html
* This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-0209).
* This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2188).
* This update resolves multiple memory corruption vulnerabilities that could lead to code execution (CVE-2010-2213).
* This update resolves a memory corruption vul
Bugzilla
CVE-2010-2483 libtiff: out-of-bounds read crash on images with invalid SamplesPerPixel values
bugzilla·2010-07-06·CVSS 4.3
CVE-2010-2483 [MEDIUM] CVE-2010-2483 libtiff: out-of-bounds read crash on images with invalid SamplesPerPixel values
CVE-2010-2483 libtiff: out-of-bounds read crash on images with invalid SamplesPerPixel values
The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers
to cause a denial of service (out-of-bounds read and application
crash) via a TIFF file with an invalid combination of SamplesPerPixel
and Photometric values.
References:
https://bugs.launchpad.net/bugs/591605
https://bugzilla.redhat.com/show_bug.cgi?id=603081
http://bugzilla.maptools.org/show_bug.cgi?id=2216
http://secunia.com/advisories/40422
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0519 https://rhn.redhat.com/errata/RHSA-2010-0519.html
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=128767780602751&w=2http://secunia.com/advisories/43026http://security.gentoo.org/glsa/glsa-201101-09.xmlhttp://support.apple.com/kb/HT4435http://www.adobe.com/support/security/bulletins/apsb10-16.htmlhttp://www.securityfocus.com/bid/42362http://www.securitytracker.com/id?1024621http://www.vupen.com/english/advisories/2011/0192https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11977https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16177http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://marc.info/?l=bugtraq&m=128767780602751&w=2http://secunia.com/advisories/43026http://security.gentoo.org/glsa/glsa-201101-09.xmlhttp://support.apple.com/kb/HT4435http://www.adobe.com/support/security/bulletins/apsb10-16.htmlhttp://www.securityfocus.com/bid/42362http://www.securitytracker.com/id?1024621http://www.vupen.com/english/advisories/2011/0192https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11977https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16177
2010-08-11
Published