VYPR
Unrated severityNVD Advisory· Published Nov 7, 2010· Updated Apr 29, 2026

CVE-2010-3646

CVE-2010-3646

Description

Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643, CVE-2010-3644, CVE-2010-3645, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649, CVE-2010-3650, and CVE-2010-3652.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 (desktop) and 10.1.95.1 (Android) has an unspecified memory corruption vulnerability allowing arbitrary code execution or denial of service via unknown vectors.

Vulnerability

Adobe Flash Player versions before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, as well as 10.1.95.1 on Android, contain an unspecified memory corruption vulnerability. The exact code path and conditions required are not disclosed, but the issue is triggered via unknown vectors [1].

Exploitation

An attacker can exploit this vulnerability by convincing a user to open a specially crafted Flash file or visit a web page hosting malicious Flash content. No authentication is required, and the attack can be delivered remotely. The specific exploitation steps are not publicly detailed due to the unspecified nature of the vulnerability.

Impact

Successful exploitation allows an attacker to execute arbitrary code on the affected system, potentially gaining full control, or to cause a denial of service (memory corruption). The impact is at the privilege level of the user running the Flash Player instance.

Mitigation

Adobe released fixed versions: 9.0.289.0 for the 9.x branch, 10.1.102.64 for desktop 10.x, and 10.1.95.1 for Android. Users should update to these versions or later. No workarounds are documented. The vulnerability is listed in HP security bulletin HPSBMA02663 [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

21

News mentions

0

No linked articles in our index yet.