CVE-2010-2180 is a critical memory corruption vulnerability affecting Adobe Flash Player before versions 9.0.277.0 and 10.1.53.64, and Adobe AIR before 2.0.2.12610. This flaw allows attackers to cause a denial of service or potentially execute arbitrary code through unspecified vectors. With a CVSS score of 9.3, it represents a high-severity risk, indicating that it can be exploited remotely with medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While the vulnerability has a high FAUCET Risk Score of 75/100 and some community discussion, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.16CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.16:*:*:*:*:*:*:* | ||
9.0.20CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.20:*:*:*:*:*:*:* | ||
9.0.20.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.20.0:*:*:*:*:*:*:* | ||
9.0.28CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.28:*:*:*:*:*:*:* | ||
9.0.28.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:9.0.28.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.