CVE-2010-3976

EUVD-2010-3953
Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Flash Player.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
adobeflash_player
𝑥
≤ 9.0.277.0
adobeflash_player
9.0.16
adobeflash_player
9.0.18d60:d60
adobeflash_player
9.0.20
adobeflash_player
9.0.20.0
adobeflash_player
9.0.28
adobeflash_player
9.0.28.0
adobeflash_player
9.0.31
adobeflash_player
9.0.31.0
adobeflash_player
9.0.45.0
adobeflash_player
9.0.47.0
adobeflash_player
9.0.48.0
adobeflash_player
9.0.112.0
adobeflash_player
9.0.114.0
adobeflash_player
9.0.115.0
adobeflash_player
9.0.124.0
adobeflash_player
9.0.125.0
adobeflash_player
9.0.151.0
adobeflash_player
9.0.152.0
adobeflash_player
9.0.155.0
adobeflash_player
9.0.159.0
adobeflash_player
9.0.246.0
adobeflash_player
9.0.260.0
adobeflash_player
9.0.262.0
adobeflash_player
𝑥
≤ 10.1.92.10
adobeflash_player
10.0.0.584
adobeflash_player
10.0.12.10
adobeflash_player
10.0.12.36
adobeflash_player
10.0.15.3
adobeflash_player
10.0.22.87
adobeflash_player
10.0.32.18
adobeflash_player
10.0.42.34
adobeflash_player
10.0.45.2
adobeflash_player
10.1.52.14.1
adobeflash_player
10.1.52.15
adobeflash_player
10.1.53.64
adobeflash_player
10.1.82.76
adobeflash_player
10.1.85.3
adobeflash_player
10.1.92.8
adobeflash_player
10.1.95.1
adobeflash_player
10.1.95.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flashplugin-nonfree
dapper
not-affected
hardy
not-affected
jaunty
ignored
karmic
not-affected
lucid
not-affected
maverick
not-affected
References