CVE-2009-1860
published 2009-06-25CVE-2009-1860: Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content.
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.65%
92.0th percentile
Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | shockwave_player | <= 11.5.0.596 | — |
| adobe | shockwave_player | <= 11.0.0.456 | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v9mm-j6r3-xv8r: Unspecified vulnerability in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2009-2186 [CRITICAL] GHSA-v9mm-j6r3-xv8r: Unspecified vulnerability in Adobe Shockwave Player before 11
Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave Player 11.0.0.465."
GHSA
GHSA-53hq-292w-c5q5: Unspecified vulnerability in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-02
CVE-2009-1860 [HIGH] GHSA-53hq-292w-c5q5: Unspecified vulnerability in Adobe Shockwave Player before 11
Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/35544http://www.adobe.com/support/security/bulletins/apsb09-08.htmlhttp://www.securityfocus.com/bid/35469http://www.securitytracker.com/id?1022440http://secunia.com/advisories/35544http://www.adobe.com/support/security/bulletins/apsb09-08.htmlhttp://www.securityfocus.com/bid/35469http://www.securitytracker.com/id?1022440
2009-06-25
Published