CVE-2010-4195

critical

Description

The TextXtra module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.

References

http://www.vupen.com/english/advisories/2011/0335

http://www.securitytracker.com/id?1025056

http://www.securityfocus.com/bid/46336

http://www.kb.cert.org/vuls/id/189929

http://www.adobe.com/support/security/bulletins/apsb11-01.html

Details

Source: Mitre, NVD

Published: 2011-02-10

Updated: 2011-02-17

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical