CVE-2010-2879

Multiple integer overflows in the allocator in the TextXtra.x32 module in Adobe Shockwave Player before 11.5.8.612 allow remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted (1) element count or (2) element size value in a file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:shockwave_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:1.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:2.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:3.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:4.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:5.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:6.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.0.196:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.0.196a:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.0.204:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.0.205:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.1.100:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.1.103:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.1.105:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.1.106:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.321:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.323:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.324:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.325:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:9:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:9.0.383:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:9.0.432:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.0.0.210:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.0.1.004:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.1.0.011:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.1.1.016:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.1.4.020:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.2.0.021:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.2.0.022:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.2.0.023:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.0.0.456:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.0.3.471:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.0.595:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.0.596:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.1.601:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.2.602:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.6.606:*:*:*:*:*:*:*

History

21 Nov 2024, 01:17

Type Values Removed Values Added
References () http://dvlabs.tippingpoint.com/advisory/TPTI-10-12 - () http://dvlabs.tippingpoint.com/advisory/TPTI-10-12 -
References () http://www.adobe.com/support/security/bulletins/apsb10-20.html - Patch, Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb10-20.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/513300/100/0/threaded - () http://www.securityfocus.com/archive/1/513300/100/0/threaded -
References () http://www.securitytracker.com/id?1024361 - () http://www.securitytracker.com/id?1024361 -
References () http://www.vupen.com/english/advisories/2010/2176 - () http://www.vupen.com/english/advisories/2010/2176 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11998 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11998 -

Information

Published : 2010-08-26 21:00

Updated : 2024-11-21 01:17


NVD link : CVE-2010-2879

Mitre link : CVE-2010-2879

CVE.ORG link : CVE-2010-2879


JSON object : View

Products Affected

adobe

  • shockwave_player
CWE
CWE-189

Numeric Errors