CVE-2010-1280 is a critical memory corruption vulnerability in Adobe Shockwave Player versions prior to 11.5.7.609, affecting both Windows and macOS systems. It allows remote attackers to execute arbitrary code or cause a denial of service through specially crafted .dir files. With a CVSS score of 8.8 (HIGH), exploitation requires user interaction (UI:R) but can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While not currently on CISA's KEV catalog, public exploit code exists (EDB-12578), though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.5.7.609CPE matchmatch criteria | cpe:2.3:a:adobe:shockwave_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.