CVE-2010-0128

Description

Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.216

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.6.606Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player for Mac 11.5.6.606Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309312Adobe Shockwave Player (12.3.5.205)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234