Adobe Shockwave Player vulnerabilities
173 known vulnerabilities affecting adobe/shockwave_player.
Total CVEs
173
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL160HIGH10MEDIUM3
Vulnerabilities
Page 1 of 9
CVE-2010-3653P2CRITICALCVSS 9.3ExploitedPoC≤ 11.5.8.612v1.0+38 more2010-10-26
CVE-2010-3653 [CRITICAL] CWE-119 CVE-2010-3653: The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value is used as a pointer offset, as exploited in the wild in October 2010. NOTE: some of these detail
nvd
CVE-2010-1280P3HIGHCVSS 8.8PoCfixed in 11.5.7.6092010-05-13
CVE-2010-1280 [HIGH] CWE-787 CVE-2010-1280: Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.
nvd
CVE-2009-3244P3CRITICALCVSS 9.3PoC≤ 11.5.1.601v1.0+39 more2009-09-18
CVE-2009-3244 [CRITICAL] CWE-119 CVE-2009-3244: Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and
Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.
nvd
CVE-2010-2866P3CRITICALCVSS 9.3PoC≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2866 [CRITICAL] CWE-189 CVE-2010-2866: Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows rem
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a Director movie.
nvd
CVE-2012-2031P3CRITICALCVSS 10.0≤ 11.6.4.634v1.0+47 more2012-05-09
CVE-2012-2031 [CRITICAL] CVE-2012-2031: Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denia
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2032, and CVE-2012-2033.
nvd
CVE-2011-2112P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2112 [CRITICAL] CWE-119 CVE-2011-2112: Multiple buffer overflows in IML32.dll in Adobe Shockwave Player before 11.6.0.626 allow attackers t
Multiple buffer overflows in IML32.dll in Adobe Shockwave Player before 11.6.0.626 allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-4176P3CRITICALCVSS 10.0≤ 11.6.7.637v1.0+48 more2012-10-23
CVE-2012-4176 [CRITICAL] CWE-20 CVE-2012-4176: Array index error in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary
Array index error in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2011-2115P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2115 [CRITICAL] CVE-2011-2115: IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary c
IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted tSAC chunk, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2011-2111 and CVE-2011-2116.
nvd
CVE-2013-0636P3CRITICALCVSS 10.0≤ 11.6.8.638v1.0+49 more2013-02-13
CVE-2013-0636 [CRITICAL] CWE-119 CVE-2013-0636: Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute
Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2011-2109P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2109 [CRITICAL] CWE-189 CVE-2011-2109: Multiple integer overflows in Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allow attackers
Multiple integer overflows in Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2011-2123P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2123 [CRITICAL] CWE-189 CVE-2011-2123: Integer overflow in the Shockwave 3D Asset x32 component in Adobe Shockwave Player before 11.6.0.626
Integer overflow in the Shockwave 3D Asset x32 component in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code via a crafted subrecord in a DEMX chunk, which triggers a heap-based buffer overflow.
nvd
CVE-2012-4172P3CRITICALCVSS 10.0≤ 11.6.7.637v1.0+48 more2012-10-23
CVE-2012-4172 [CRITICAL] CWE-119 CVE-2012-4172: Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary co
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.
nvd
CVE-2012-4174P3CRITICALCVSS 10.0≤ 11.6.7.637v1.0+48 more2012-10-23
CVE-2012-4174 [CRITICAL] CVE-2012-4174: Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary co
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4175, and CVE-2012-5273.
nvd
CVE-2012-4175P3CRITICALCVSS 10.0≤ 11.6.7.637v1.0+48 more2012-10-23
CVE-2012-4175 [CRITICAL] CVE-2012-4175: Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary co
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-5273.
nvd
CVE-2012-4173P3CRITICALCVSS 10.0≤ 11.6.7.637v1.0+48 more2012-10-23
CVE-2012-4173 [CRITICAL] CVE-2012-4173: Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary co
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.
nvd
CVE-2011-2118P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2118 [CRITICAL] CWE-20 CVE-2011-2118: The FLV ASSET Xtra component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute
The FLV ASSET Xtra component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors, related to an "input validation vulnerability."
nvd
CVE-2012-5273P3CRITICALCVSS 10.0≤ 11.6.7.637v1.0+48 more2012-10-23
CVE-2012-5273 [CRITICAL] CVE-2012-5273: Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary co
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175.
nvd
CVE-2014-0501P3CRITICALCVSS 10.0≤ 12.0.7.148v11.0.0.456+24 more2014-02-12
CVE-2014-0501 [CRITICAL] CVE-2014-0501: Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause
Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0500.
nvd
CVE-2013-1383P3CRITICALCVSS 10.0≤ 12.0.0.112v1.0+51 more2013-04-10
CVE-2013-1383 [CRITICAL] CWE-119 CVE-2013-1383: Buffer overflow in Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary co
Buffer overflow in Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2014-0500P3CRITICALCVSS 10.0≤ 12.0.7.148v11.0.0.456+24 more2014-02-12
CVE-2014-0500 [CRITICAL] CWE-119 CVE-2014-0500: Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause
Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0501.
nvd
1 / 9Next →