CVE-2010-4085
published 2010-10-29CVE-2010-4085: dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.18%
89.7th percentile
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4084, CVE-2010-4086, and CVE-2010-4088.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | shockwave_player | <= 11.5.8.612 | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p37h-qw4w-9q65: dirapi
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2010-4085 [CRITICAL] CWE-119 GHSA-p37h-qw4w-9q65: dirapi
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4084, CVE-2010-4086, and CVE-2010-4088.
GHSA
GHSA-3w2w-5pxh-222c: dirapi
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2010-4084 [CRITICAL] CWE-119 GHSA-3w2w-5pxh-222c: dirapi
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.
GHSA
GHSA-pj49-56rq-x2cw: dirapi
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-4088 [CRITICAL] CWE-119 GHSA-pj49-56rq-x2cw: dirapi
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file with "duplicated references to the same KEY* chunk," a different vulnerability than CVE-2010-2581, CVE-2010-4084, CVE-2010-4085, and CVE-2010-4086.
GHSA
GHSA-cpf9-x6x7-j973: dirapi
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2581 [CRITICAL] CWE-119 GHSA-cpf9-x6x7-j973: dirapi
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director file containing a crafted pamm chunk with an invalid (1) size and (2) number of sub-chunks, a different vulnerability than CVE-2010-4084, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.
GHSA
GHSA-7rfw-vg62-m5wc: dirapi
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-4086 [CRITICAL] CWE-119 GHSA-7rfw-vg62-m5wc: dirapi
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Director (.dir) media file with an invalid element size, a different vulnerability than CVE-2010-2581, CVE-2010-2880, CVE-2010-4084, CVE-2010-4085, and CVE-2010-4088.
Red Hat
Invoker servlets authentication bypass (HTTP verb tampering)
vendor_redhat·2011-11-16·CVSS 5.3
CVE-2011-4085 [MEDIUM] Invoker servlets authentication bypass (HTTP verb tampering)
Invoker servlets authentication bypass (HTTP verb tampering)
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.
No detection rules found.
http://www.adobe.com/support/security/bulletins/apsb10-25.htmlhttp://www.securitytracker.com/id?1024664https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11518http://www.adobe.com/support/security/bulletins/apsb10-25.htmlhttp://www.securitytracker.com/id?1024664https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11518
2010-10-29
Published