CVE-2010-2162 is a critical vulnerability affecting Adobe Flash Player versions prior to 9.0.277.0 and 10.1.53.64, and Adobe AIR before 2.0.2.12610. It stems from improper length calculations within specific atoms (STSC, STSZ, STCO), leading to heap memory corruption. This flaw has a CVSS score of 9.3, indicating a high severity with network-based attacks, medium complexity, and potential for complete compromise of confidentiality, integrity, and availability, including arbitrary code execution. Despite its age and severity, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion beyond a single Reddit mention of general Flash updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.16CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:* | ||
9.0.20CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:* | ||
9.0.20.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:* | ||
9.0.28CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:* | ||
9.0.28.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.