cbcvebase.

Adobe Shockwave Player vulnerabilities

173 known vulnerabilities affecting adobe/shockwave_player.

Total CVEs
173
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL160HIGH10MEDIUM3

Vulnerabilities

Page 3 of 9
CVE-2011-0557P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2011-0557 [CRITICAL] CWE-189 CVE-2011-0557: Integer overflow in Adobe Shockwave Player before 11.5.9.620 allows remote attackers to execute arbi Integer overflow in Adobe Shockwave Player before 11.5.9.620 allows remote attackers to execute arbitrary code via a Director movie with a large count value in 3D assets type 0xFFFFFF45 record, which triggers a "faulty allocation" and memory corruption.
nvd
CVE-2009-2186P3CRITICALCVSS 9.3≤ 11.0.0.456v1.0+9 more2009-06-25
CVE-2009-2186 [CRITICAL] CVE-2009-2186: Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to exe Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave Player 11.0.0.465."
nvd
CVE-2011-2120P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2120 [CRITICAL] CWE-189 CVE-2011-2120: Integer overflow in the CursorAsset x32 component in Adobe Shockwave Player before 11.6.0.626 allows Integer overflow in the CursorAsset x32 component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-0987P3HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-0987 [HIGH] CWE-787 CVE-2010-0987: Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file.
nvd
CVE-2010-3655P3CRITICALCVSS 9.3≤ 11.5.8.612v1.0+39 more2010-10-29
CVE-2010-3655 [CRITICAL] CWE-119 CVE-2010-3655: Stack-based buffer overflow in dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attacke Stack-based buffer overflow in dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-6271P3CRITICALCVSS 9.3≤ 11.6.8.638v1.0+49 more2012-12-20
CVE-2012-6271 [CRITICAL] CVE-2012-6271: Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitra Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via a Shockwave movie that contains an Xtra URL, as demonstrated by a URL for an outdated Xtra.
nvd
CVE-2009-4002P3CRITICALCVSS 9.3≤ 11.5.2.602v1.0+13 more2010-01-21
CVE-2009-4002 [CRITICAL] CWE-119 CVE-2009-4002: Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to ex Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file.
nvd
CVE-2017-3086P3CRITICALCVSS 9.8≤ 12.2.8.1982017-06-20
CVE-2017-3086 [CRITICAL] CWE-119 CVE-2017-3086: Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2012-0758P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0758 [CRITICAL] CWE-119 CVE-2012-0758: Heap-based buffer overflow in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute a Heap-based buffer overflow in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2009-4003P3CRITICALCVSS 9.3≤ 11.5.2.602v1.0+13 more2010-01-21
CVE-2009-4003 [CRITICAL] CWE-189 CVE-2009-4003: Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to exe Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corru
nvd
CVE-2010-2873P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2873 [CRITICAL] CWE-20 CVE-2010-2873: Adobe Shockwave Player before 11.5.8.612 does not properly validate offset values in the rcsL RIFF c Adobe Shockwave Player before 11.5.8.612 does not properly validate offset values in the rcsL RIFF chunks of (1) .DIR and (2) .DCR Director movies, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.
nvd
CVE-2011-2121P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2121 [CRITICAL] CWE-189 CVE-2011-2121: Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary c Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-2876P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2876 [CRITICAL] CWE-20 CVE-2010-2876: Adobe Shockwave Player before 11.5.8.612 does not properly validate values associated with buffer-si Adobe Shockwave Player before 11.5.8.612 does not properly validate values associated with buffer-size calculation for a 0xFFFFFFF8 record in a (1) .dir or (2) .dcr Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.
nvd
CVE-2010-2872P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2872 [CRITICAL] CWE-20 CVE-2010-2872: Adobe Shockwave Player before 11.5.8.612 does not properly validate an offset value in the pami RIFF Adobe Shockwave Player before 11.5.8.612 does not properly validate an offset value in the pami RIFF chunk in a Director movie, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted movie.
nvd
CVE-2010-1288P3CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1288 [CRITICAL] CWE-119 CVE-2010-1288: Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitra Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-4194P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2010-4194 [CRITICAL] CWE-20 CVE-2010-4194: The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspeci The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 does not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2019-7102P3CRITICALCVSS 9.8≤ 12.3.4.2042019-05-23
CVE-2019-7102 [CRITICAL] CWE-787 CVE-2019-7102: Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Succe Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-7101P3CRITICALCVSS 9.8≤ 12.3.4.2042019-05-23
CVE-2019-7101 [CRITICAL] CWE-787 CVE-2019-7101: Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Succe Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2010-1283P3HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-1283 [HIGH] CWE-787 CVE-2010-1283: Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) f Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record.
nvd
CVE-2010-4190P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2010-4190 [CRITICAL] CVE-2010-4190: Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted CSWV RIFF chunk that causes an incorrect calculation of an offset for a substructure, which causes an out-of-bounds "seek" of heap memory, a different vulnerability than CVE-2011-0555, CVE-2
nvd
Adobe Shockwave Player vulnerabilities | cvebase