CVE-2010-4194

critical

Description

The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.

References

http://www.vupen.com/english/advisories/2011/0335

http://www.securitytracker.com/id?1025056

http://www.securityfocus.com/bid/46335

http://www.kb.cert.org/vuls/id/189929

http://www.adobe.com/support/security/bulletins/apsb11-01.html

Details

Source: Mitre, NVD

Published: 2011-02-10

Updated: 2011-02-17

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical