FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-3637

This CVE name corresponds to:

Entered Topic
2010-11-06 linux-flashplugin -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-3637
Phase Assigned(20100928)

Description

An unspecified ActiveX control in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 (Flash10h.ocx) on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FLV video.

References

Source Reference
BUGTRAQ 20101105 [FG-VD-10-020]Adobe Flash Player Remote Memory corruption Vulnerability
CONFIRM http://www.adobe.com/support/security/bulletins/apsb10-26.html
CONFIRM http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe_flash1
HP HPSBMA02663
HP SSRT100428
SUSE SUSE-SA:2010:055
BID 44690
OVAL oval:org.mitre.oval:def:12259
SECUNIA 42926
VUPEN ADV-2010-2903
VUPEN ADV-2011-0173