CVE-2010-3639
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 22%
from disclosure to weapon0 days
Published on NVDNov 7
1st PoCNov 5
exploitation probability
22%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/15426⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe_flash1http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00002.htmlhttp://marc.info/?l=bugtraq&m=130331642631603&w=2http://secunia.com/advisories/42183http://secunia.com/advisories/42926http://secunia.com/advisories/43026http://security.gentoo.org/glsa/glsa-201101-09.xmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11310https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12625http://support.apple.com/kb/HT4435http://www.adobe.com/support/security/bulletins/apsb10-26.html