Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-2874

EPSS 7.89% · P92
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-2874

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption. NOTE: due to conflicting information and use of the same CVE identifier by the vendor, ZDI, and TippingPoint, it is not clear whether this issue is related to use of an uninitialized pointer, an incorrect pointer offset calculation, or both.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Adobe Shockwave Player未明漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Adobe Shockwave Player是美国奥多比(Adobe)公司的一款多媒体播放器产品,它能够将Adobe Director(一款多媒体制作软件)制作的应用程序发布到互联网上,安装有Shockwave插件的浏览器可对其进行浏览。 Shockwave Player中负责解析Director电影的DIRAPIX.dll库存在内存破坏漏洞。有漏洞的代码将从输入文件获得的值通过添加符号进行了扩展并将其用作了偏移以便在执行写操作之前查找堆缓冲区。通过为这个字段创建特制的值,攻击者就可以强制进程越界查找缓冲
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-2874

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-2874

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-09-07 · 26 CVEs total

CVE-2010-3251Google Chrome WebSockets实施资源管理错误漏洞
CVE-2010-2802MantisBT跨站脚本攻击漏洞
CVE-2010-2521Linux kernel 缓冲区错误漏洞
CVE-2010-2248Linux kernel 输入验证错误漏洞
CVE-2009-4898TWiki跨站请求伪造漏洞
CVE-2010-3259WebKit图像读取权限许可和访问控制问题漏洞
CVE-2010-3258Google Chrome沙盒资源管理错误漏洞
CVE-2010-3257WebKit释放后使用漏洞
CVE-2010-3256Google Chrome存储自动化资源管理错误漏洞
CVE-2010-3255Google Chrome和webkitgtk输入验证错误漏洞
CVE-2010-3254Google Chrome数字错误漏洞
CVE-2010-3253Google Chrome权限通知资源管理错误漏洞
CVE-2010-3252Google Chrome Notifications presenter释放后使用漏洞
CVE-2006-7240gnome-power-manager权限许可和访问控制漏洞
CVE-2010-3250Google Chrome未明漏洞
CVE-2010-3249Google Chrome SVG过滤器资源管理错误漏洞
CVE-2010-3248Google Chrome 复制功能权限许可和访问控制问题漏洞
CVE-2010-3247Google Chrome URL输入验证错误漏洞
CVE-2010-3246Google Chrome输入验证错误漏洞
CVE-2010-3245Blackboard Transact Suite自动备份功能存储信息泄露漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-2874

No comments yet


Leave a comment