CVE-2010-1292 describes a critical vulnerability in Adobe Shockwave Player versions prior to 11.5.7.609, affecting systems running Adobe, Apple, and Microsoft products. The flaw resides in the pami RIFF chunk parsing, where improper validation of a file value leads to incorrect file-pointer calculations. This allows remote attackers to execute arbitrary code or cause a denial of service through memory corruption via a specially crafted .dir file. With a CVSS score of 9.3, this vulnerability is considered critical due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score of 83/100 further emphasizes its high severity. Despite its high severity, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.5.6.606CPE matchmatch criteria | cpe:2.3:a:adobe:shockwave_player:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:adobe:shockwave_player:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:adobe:shockwave_player:2.0:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:adobe:shockwave_player:3.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:adobe:shockwave_player:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.