← Vulnerability feed

Vulnerability record · CVE-2010-3654 · published 29 October 2010

CVE-2010-3654: Adobe Flash Player and Reader memory corruption via crafted SWF

Adobe · Flash Player

Adobe Flash Player (before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux and Solaris, and 10.1.95.1 on Android) and authplay.dll in Adobe Reader and Acrobat 9.x through 9.4 contain a memory corruption flaw (CWE-119) triggered by crafted SWF content. It allows remote code execution or denial of service and was exploited in the wild in October 2010, making it a serious client-side risk for unpatched systems.

9.3 CVSS 2.0 High EPSS 70% · top 0.7% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
74References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote code execution with confirmed in-the-wild exploitation and very high EPSS, though the flaw is old and patched, so risk is concentrated on unpatched or legacy systems.

What it is

Adobe Flash Player (before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux and Solaris, and 10.1.95.1 on Android) and authplay.dll in Adobe Reader and Acrobat 9.x through 9.4 contain a memory corruption flaw (CWE-119) triggered by crafted SWF content. It allows remote code execution or denial of service and was exploited in the wild in October 2010, making it a serious client-side risk for unpatched systems.

Impact

An attacker can execute arbitrary code in the context of the affected application or crash it, giving full control of confidentiality, integrity and availability per the CVSS vector. In practice this means code execution on the victim's machine through a malicious SWF.

Attack surface

Reached remotely over the network by delivering crafted SWF content to Flash Player or to the authplay component embedded in Reader/Acrobat; no authentication is required, but the CVSS vector shows medium attack complexity and typically requires the user to open or render the malicious content.

Exploitation

The description states it was exploited in the wild in October 2010 and one reference is tagged Exploit, while EPSS is high (0.69679, 99.3rd percentile); it is not listed in CISA KEV.

What to do

  • Update Flash Player to 9.0.289.0 or later, or 10.1.102.64 or later (10.1.95.1 on Android), and apply the corresponding Adobe Reader/Acrobat updates referenced in Adobe advisories APSA10-05, APSB10-26 and APSB10-28.
  • Apply vendor patches for Reader/Acrobat authplay.dll and for Linux distributions (Red Hat, openSUSE, Gentoo) and Apple/Solaris platforms listed in the references.
  • Disable or remove Flash content rendering where it is not required, and disable JavaScript/embedded content in Reader and Acrobat if feasible.
  • Block or restrict untrusted SWF files at email and web gateways, and enforce browser plug-in click-to-play so SWF content does not render automatically.

Detection

  • Monitor for Reader, Acrobat or Flash Player processes spawning child processes or making unexpected network connections, which can indicate successful exploitation.
  • Hunt for crash reports or event logs from Flash Player, Reader or Acrobat referencing memory corruption or authplay module faults.
  • Search email and web proxy logs for SWF attachments or downloads from untrusted sources delivered around the exploitation window.
  • Use endpoint detection to flag known exploit artifacts or shellcode behavior in processes loading authplay.dll, AuthPlayLib.bundle or libauthplay.so.0.0.0.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe_flash1
http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html Exploit
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00001.html
http://secunia.com/advisories/41917 Vendor Advisory
http://secunia.com/advisories/42030
http://secunia.com/advisories/42183
http://secunia.com/advisories/42401
http://secunia.com/advisories/42926
http://secunia.com/advisories/43025
http://secunia.com/advisories/43026
http://security.gentoo.org/glsa/glsa-201101-08.xml
http://security.gentoo.org/glsa/glsa-201101-09.xml
http://securityreason.com/securityalert/8210
http://support.apple.com/kb/HT4435
http://www.adobe.com/support/security/advisories/apsa10-05.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb10-26.html
http://www.adobe.com/support/security/bulletins/apsb10-28.html
http://www.kb.cert.org/vuls/id/298081 US Government Resource
http://www.redhat.com/support/errata/RHSA-2010-0829.html
http://www.redhat.com/support/errata/RHSA-2010-0834.html
http://www.redhat.com/support/errata/RHSA-2010-0867.html
http://www.redhat.com/support/errata/RHSA-2010-0934.html
http://www.securityfocus.com/bid/44504
http://www.securitytracker.com/id?1024659
http://www.securitytracker.com/id?1024660
http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txt
http://www.vupen.com/english/advisories/2010/2903
http://www.vupen.com/english/advisories/2010/2906
http://www.vupen.com/english/advisories/2010/2918
http://www.vupen.com/english/advisories/2010/3111
http://www.vupen.com/english/advisories/2011/0173
http://www.vupen.com/english/advisories/2011/0191
http://www.vupen.com/english/advisories/2011/0192
http://www.vupen.com/english/advisories/2011/0344
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13294
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe_flash1
http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html Exploit
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html

Track CVE-2010-3654 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2015-3043Adobe Flash Player memory corruption allows arbitrary code executionAdobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. Th…KEVEPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2010-3654), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.