VYPR
Unrated severityNVD Advisory· Published Nov 7, 2010· Updated Apr 29, 2026

CVE-2010-3640

CVE-2010-3640

Description

Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3641, CVE-2010-3642, CVE-2010-3643, CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649, CVE-2010-3650, and CVE-2010-3652.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 (and 10.1.95.1 on Android) contain an unspecified memory corruption vulnerability that allows arbitrary code execution or denial of service via unknown vectors.

Vulnerability

Adobe Flash Player versions before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android contain an unspecified memory corruption vulnerability. The vulnerability can be triggered via unknown vectors, leading to arbitrary code execution or denial of service [1].

Exploitation

The exact exploitation method is not publicly disclosed. An attacker would need to entice a user to view a malicious Flash file, possibly via a web page or email. No authentication or special privileges are required beyond normal user interaction [1].

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the affected user, potentially gaining full control of the system, or cause a denial of service through memory corruption. The impact is consistent with other Flash Player vulnerabilities from this series [1].

Mitigation

Adobe released fixes in Flash Player 9.0.289.0, 10.1.102.64, and 10.1.95.1 for Android. Affected users should update to the latest versions. Red Hat and HP have issued related advisories [2][3][4].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

21

News mentions

0

No linked articles in our index yet.