Adobe Shockwave Player vulnerabilities

173 known vulnerabilities affecting adobe/shockwave_player.

Total CVEs
173
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL160HIGH10MEDIUM3

Vulnerabilities

Page 4 of 9
CVE-2010-4308CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2010-4308 [CRITICAL] CWE-119 CVE-2010-4308: Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4309.
nvd
CVE-2011-2421CRITICALCVSS 9.3≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2421 [CRITICAL] CWE-119 CVE-2011-2421: Dirapi.dll in Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or Dirapi.dll in Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir media file.
nvd
CVE-2011-2422CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2422 [CRITICAL] CWE-119 CVE-2011-2422: Textra.x32 in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary Textra.x32 in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2420CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2420 [CRITICAL] CWE-119 CVE-2011-2420: Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2419CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2419 [CRITICAL] CWE-119 CVE-2011-2419: IML32.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary c IML32.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2423CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2423 [CRITICAL] CWE-119 CVE-2011-2423: msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2010-4309CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2010-4309 [CRITICAL] CVE-2010-4309: Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4308.
nvd
CVE-2011-0335CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-0335 [CRITICAL] CVE-2011-0335: Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0318, CVE-2011-0319, CVE-2011-0320, CVE-2011-2119, and CVE-2011-2122.
nvd
CVE-2011-2115CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2115 [CRITICAL] CVE-2011-2115: IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary c IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted tSAC chunk, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2011-2111 and CVE-2011-2116.
nvd
CVE-2011-2128CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2128 [CRITICAL] CVE-2011-2128: Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2114, CVE-2011-2117, CVE-2011-2124, and CVE-2011-2127.
nvd
CVE-2011-2113CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2113 [CRITICAL] CWE-119 CVE-2011-2113: Multiple buffer overflows in the Shockwave3DAsset component in Adobe Shockwave Player before 11.6.0. Multiple buffer overflows in the Shockwave3DAsset component in Adobe Shockwave Player before 11.6.0.626 allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2011-2121CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2121 [CRITICAL] CWE-189 CVE-2011-2121: Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary c Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2011-2124CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2124 [CRITICAL] CVE-2011-2124: Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2114, CVE-2011-2117, CVE-2011-2127, and CVE-2011-2128.
nvd
CVE-2011-2114CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2114 [CRITICAL] CWE-119 CVE-2011-2114: Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2117, CVE-2011-2124, CVE-2011-2127, and CVE-2011-2128.
nvd
CVE-2011-2118CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2118 [CRITICAL] CWE-20 CVE-2011-2118: The FLV ASSET Xtra component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute The FLV ASSET Xtra component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors, related to an "input validation vulnerability."
nvd
CVE-2011-0317CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-0317 [CRITICAL] CWE-119 CVE-2011-0317: Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0318, CVE-2011-0319, CVE-2011-0320, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.
nvd
CVE-2011-0319CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-0319 [CRITICAL] CVE-2011-0319: Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0318, CVE-2011-0320, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.
nvd
CVE-2011-2111CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2111 [CRITICAL] CWE-119 CVE-2011-2111: IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2115 and CVE-2011-2116.
nvd
CVE-2011-2108CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2108 [CRITICAL] CVE-2011-2108: Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors, related to a "design flaw."
nvd
CVE-2011-2123CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2123 [CRITICAL] CWE-189 CVE-2011-2123: Integer overflow in the Shockwave 3D Asset x32 component in Adobe Shockwave Player before 11.6.0.626 Integer overflow in the Shockwave 3D Asset x32 component in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code via a crafted subrecord in a DEMX chunk, which triggers a heap-based buffer overflow.
nvd