Multiple heap-based buffer overflows in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to malformed (1) GIF or (2) JPEG data.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Jun 15, 2010 |
| Adobe Apsb10 14 Adobe Flash Multiple Unspecified Heap Overflows | — | Upgrade to Adobe Flash Player version 10.1.53.64 for LinuxUpgrade to Adobe Flash Player version 9.0.277.0 for LinuxUpgrade to Adobe Flash Player version 9.0.277.0 for Mac OS XUpgrade to Adobe Flash Player version 10.1.53.64 for WindowsUpgrade to Adobe Flash Player version 9.0.277.0 for WindowsUpgrade to Adobe Flash Player version 10.1.53.64 for Mac OS X | Jun 17, 2010 | Jun 15, 2010 |
| Apple Osx Flashplayerplugin | — | Upgrade macOS to the latest versionApply OS X security update 2010-007 | Dec 16, 2011 | Jun 15, 2010 |
| Freebsd | — | Upgrade linux-f8-flashpluginUpgrade linux-f10-flashpluginUpgrade linux-flashplugin | Dec 10, 2025 | Jun 14, 2010 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jun 15, 2010 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Jun 15, 2010 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-gnome | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Jun 15, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub