CVE-2010-1278 is a critical buffer overflow vulnerability affecting the Atlcom.get_atlcom ActiveX control in gp.ocx within Adobe Download Manager, impacting Adobe Reader and Acrobat versions 8.x prior to 8.2 and 9.x prior to 9.3. This flaw allows remote attackers to execute arbitrary code on a vulnerable system through unspecified parameters, posing a significant risk. With a CVSS score of 9.3, it is a high-severity vulnerability that can be exploited with medium attack complexity over a network, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been identified, and community discussion is minimal, the potential impact remains severe.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:reader:8.0.0:*:*:*:*:*:*:* | ||
8.1.1CPE matchmatch criteria | cpe:2.3:a:adobe:reader:8.1.1:*:*:*:*:*:*:* | ||
8.1.2CPE matchmatch criteria | cpe:2.3:a:adobe:reader:8.1.2:*:*:*:*:*:*:* | ||
8.1.4CPE matchmatch criteria | cpe:2.3:a:adobe:reader:8.1.4:*:*:*:*:*:*:* | ||
8.1.5CPE matchmatch criteria | cpe:2.3:a:adobe:reader:8.1.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.