CVE-2010-2873

9.3
CVSS v2.0 Base Score
6.25%
LOW RiskEPSS (93rd percentile)

Adobe Shockwave Player before 11.5.8.612 does not properly validate offset values in the rcsL RIFF chunks of (1) .DIR and (2) .DCR Director movies, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.

Published: 8/26/2010
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

9.3

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

6.25%LOW Exploitation Risk
93rd percentile

This vulnerability has a 6.25% probability of being exploited in the next 30 days, ranking higher than 93% of all scored CVEs.

CWE Classification

Advertisement