CVE-2010-1280
HIGHAdobe Shockwave Player <11.5.7.609 - RCE/DoS
Title source: llmDescription
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by LiquidWorm · cdoswindows
https://www.exploit-db.com/exploits/12578
References (8)
Scores
CVSS v3
8.8
EPSS
0.3564
EPSS Percentile
97.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (1)
adobe/shockwave_player
< 11.5.7.609
Published
May 13, 2010
Tracked Since
Feb 18, 2026