cbcvebase.

Adobe Shockwave Player vulnerabilities

173 known vulnerabilities affecting adobe/shockwave_player.

Total CVEs
173
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL160HIGH10MEDIUM3

Vulnerabilities

Page 4 of 9
CVE-2011-2423P3CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2423 [CRITICAL] CWE-119 CVE-2011-2423: msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2012-2029P3CRITICALCVSS 10.0≤ 11.6.4.634v1.0+47 more2012-05-09
CVE-2012-2029 [CRITICAL] CWE-119 CVE-2012-2029: Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2030, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.
nvd
CVE-2012-2030P3CRITICALCVSS 10.0≤ 11.6.4.634v1.0+47 more2012-05-09
CVE-2012-2030 [CRITICAL] CVE-2012-2030: Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.
nvd
CVE-2012-2032P3CRITICALCVSS 10.0≤ 11.6.4.634v1.0+47 more2012-05-09
CVE-2012-2032 [CRITICAL] CVE-2012-2032: Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2033.
nvd
CVE-2012-2033P3CRITICALCVSS 10.0≤ 11.6.4.634v1.0+47 more2012-05-09
CVE-2012-2033 [CRITICAL] CVE-2012-2033: Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2032.
nvd
CVE-2012-0764P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0764 [CRITICAL] CVE-2012-0764: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to exe The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0766.
nvd
CVE-2011-2422P3CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2422 [CRITICAL] CWE-119 CVE-2011-2422: Textra.x32 in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary Textra.x32 in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2420P3CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2420 [CRITICAL] CWE-119 CVE-2011-2420: Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2013-3360P3CRITICALCVSS 10.0≤ 12.0.3.133v1.0+53 more2013-09-12
CVE-2013-3360 [CRITICAL] CVE-2013-3360: Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3359.
nvd
CVE-2012-0762P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0762 [CRITICAL] CVE-2012-0762: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to exe The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
nvd
CVE-2012-0761P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0761 [CRITICAL] CVE-2012-0761: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to exe The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
nvd
CVE-2010-1281P3HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-1281 [HIGH] CWE-787 CVE-2010-1281: iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.
nvd
CVE-2010-2871P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2871 [CRITICAL] CWE-189 CVE-2010-2871: Integer overflow in the 3D object functionality in Adobe Shockwave Player before 11.5.8.612 allows r Integer overflow in the 3D object functionality in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted size value in a 0xFFFFFF45 RIFF record in a Director movie.
nvd
CVE-2010-2878P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2878 [CRITICAL] CWE-20 CVE-2010-2878: DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a value associate DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a value associated with a buffer seek for a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.
nvd
CVE-2011-0569P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2011-0569 [CRITICAL] CVE-2011-0569: The Font Xtra.x32 module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arb The Font Xtra.x32 module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PFR1 chunk containing an invalid size value that leads to an unexpected sign extension and a buffer overflow, a different vulnerability than CVE-2011-0556.
nvd
CVE-2010-4192P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2010-4192 [CRITICAL] CVE-2010-4192: Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted 3D Assets 0xFFFFFF88 type record that triggers an incorrect memory allocation, a different vulnerability than CVE-2011-0555, CVE-2010-4093, CVE-2010-4187, CVE-2010-4190, CVE-2010-4191, and C
nvd
CVE-2010-2589P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2010-2589 [CRITICAL] CWE-189 CVE-2010-2589: Integer overflow in the dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attacke Integer overflow in the dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-0771P3HIGHCVSS 8.8fixed in 11.6.4.6342018-02-19
CVE-2012-0771 [HIGH] CVE-2012-0771: Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759.
nvd
CVE-2015-6681P3CRITICALCVSS 10.0≤ 12.1.9.1602015-09-09
CVE-2015-6681 [CRITICAL] CVE-2015-6681: Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680.
nvd
CVE-2011-2419P3CRITICALCVSS 10.0≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2419 [CRITICAL] CWE-119 CVE-2011-2419: IML32.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary c IML32.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd