CVE-2012-0763
published 2012-02-15CVE-2012-0763: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory…
PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.79%
88.7th percentile
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0764, and CVE-2012-0766.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | shockwave_player | <= 11.6.3.633 | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
| adobe | shockwave_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwq2-mx85-4pfv: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0766 [CRITICAL] CWE-119 GHSA-wwq2-mx85-4pfv: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0764.
GHSA
GHSA-qxvj-mc2g-q6cc: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0764 [CRITICAL] CWE-119 GHSA-qxvj-mc2g-q6cc: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0766.
GHSA
GHSA-6fvv-pmpx-fp4w: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0761 [CRITICAL] CWE-119 GHSA-6fvv-pmpx-fp4w: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
GHSA
GHSA-j7x4-p5fv-986c: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0762 [CRITICAL] CWE-119 GHSA-j7x4-p5fv-986c: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
GHSA
GHSA-ghc4-x7rm-9g73: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0763 [CRITICAL] CWE-119 GHSA-ghc4-x7rm-9g73: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0764, and CVE-2012-0766.
GHSA
GHSA-cr49-49qx-f744: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0760 [CRITICAL] CWE-119 GHSA-cr49-49qx-f744: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
GHSA
GHSA-5p84-2732-cvwq: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0757 [CRITICAL] CWE-119 GHSA-5p84-2732-cvwq: The Shockwave 3D Asset component in Adobe Shockwave Player before 11
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()
vendor_redhat·2011-04-13·CVSS 7.5
CVE-2013-4357 [HIGH] CWE-121 glibc: stack overflow in getaddrinfo()'s use of alloca()
glibc: stack overflow in getaddrinfo()'s use of alloca()
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
Statement: This issue has already been addressed in Red Hat Enterprise Linux 5 via http://rhn.redhat.com/errata/RHBA-2013-0022.html and in Red Hat Enterprise Linux 6 via http://rhn.redhat.com/errata/RHBA-2012-0763.html
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()
vendor_redhat·2011-04-13·CVSS 7.5
CVE-2012-6686 [HIGH] CWE-121 glibc: stack overflow in getaddrinfo()'s use of alloca()
glibc: stack overflow in getaddrinfo()'s use of alloca()
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2013-4357. Note: All CVE users should reference CVE-2013-4357 instead of this candidate.
Statement: This issue has already been addressed in Red Hat Enterprise Linux 5 via http://rhn.redhat.com/errata/RHBA-2013-0022.html and in Red Hat Enterprise Linux 6 via http://rhn.redhat.com/errata/RHBA-2012-0763.html
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-02-15
Published