cbcvebase.

Adobe Shockwave Player vulnerabilities

173 known vulnerabilities affecting adobe/shockwave_player.

Total CVEs
173
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL160HIGH10MEDIUM3

Vulnerabilities

Page 5 of 9
CVE-2015-6680P3CRITICALCVSS 10.0≤ 12.1.9.1602015-09-09
CVE-2015-6680 [CRITICAL] CVE-2015-6680: Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681.
nvd
CVE-2013-1385P3CRITICALCVSS 10.0≤ 12.0.0.112v1.0+51 more2013-04-10
CVE-2013-1385 [CRITICAL] CWE-264 CVE-2013-1385: Adobe Shockwave Player before 12.0.2.122 does not prevent access to address information, which makes Adobe Shockwave Player before 12.0.2.122 does not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
nvd
CVE-2012-2045P3CRITICALCVSS 10.0≤ 11.6.5.635v1.0+48 more2012-08-15
CVE-2012-2045 [CRITICAL] CVE-2012-2045: Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2043, CVE-2012-2044, CVE-2012-2046, and CVE-2012-2047.
nvd
CVE-2012-2046P3CRITICALCVSS 10.0≤ 11.6.5.635v1.0+48 more2012-08-15
CVE-2012-2046 [CRITICAL] CVE-2012-2046: Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2043, CVE-2012-2044, CVE-2012-2045, and CVE-2012-2047.
nvd
CVE-2012-2044P3CRITICALCVSS 10.0≤ 11.6.5.635v1.0+48 more2012-08-15
CVE-2012-2044 [CRITICAL] CVE-2012-2044: Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2043, CVE-2012-2045, CVE-2012-2046, and CVE-2012-2047.
nvd
CVE-2012-2047P3CRITICALCVSS 10.0≤ 11.6.5.635v1.0+48 more2012-08-15
CVE-2012-2047 [CRITICAL] CVE-2012-2047: Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2043, CVE-2012-2044, CVE-2012-2045, and CVE-2012-2046.
nvd
CVE-2012-2043P3CRITICALCVSS 10.0≤ 11.6.5.635v1.0+48 more2012-08-15
CVE-2012-2043 [CRITICAL] CWE-119 CVE-2012-2043: Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2044, CVE-2012-2045, CVE-2012-2046, and CVE-2012-2047.
nvd
CVE-2010-2877P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2877 [CRITICAL] CWE-20 CVE-2010-2877: Adobe Shockwave Player before 11.5.8.612 does not properly validate a count value in a Director movi Adobe Shockwave Player before 11.5.8.612 does not properly validate a count value in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie, related to IML32X.dll and DIRAPIX.dll.
nvd
CVE-2013-5333P3CRITICALCVSS 10.0≤ 12.0.6.147v1.0+53 more2013-12-11
CVE-2013-5333 [CRITICAL] CWE-119 CVE-2013-5333: Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5334.
nvd
CVE-2013-5334P3CRITICALCVSS 10.0≤ 12.0.6.147v1.0+53 more2013-12-11
CVE-2013-5334 [CRITICAL] CVE-2013-5334: Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5333.
nvd
CVE-2013-3359P3CRITICALCVSS 10.0≤ 12.0.3.133v1.0+53 more2013-09-12
CVE-2013-3359 [CRITICAL] CWE-119 CVE-2013-3359: Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3360.
nvd
CVE-2012-0760P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0760 [CRITICAL] CVE-2012-0760: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to exe The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
nvd
CVE-2012-0763P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0763 [CRITICAL] CVE-2012-0763: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to exe The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0764, and CVE-2012-0766.
nvd
CVE-2012-0757P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0757 [CRITICAL] CWE-119 CVE-2012-0757: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to exe The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
nvd
CVE-2012-0766P3CRITICALCVSS 10.0≤ 11.6.3.633v1.0+44 more2012-02-15
CVE-2012-0766 [CRITICAL] CVE-2012-0766: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to exe The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0764.
nvd
CVE-2010-4092P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2010-11-05
CVE-2010-4092 [CRITICAL] CWE-399 CVE-2010-4092: Use-after-free vulnerability in an unspecified compatibility component in Adobe Shockwave Player bef Use-after-free vulnerability in an unspecified compatibility component in Adobe Shockwave Player before 11.5.9.620 allows user-assisted remote attackers to execute arbitrary code via a crafted web site, related to the Shockwave Settings window and an unloaded library. NOTE: some of these details are obtained from third party information.
nvd
CVE-2010-2870P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2870 [CRITICAL] CWE-119 CVE-2010-2870: DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a certain chunk s DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a certain chunk size in the mmap chunk in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.
nvd
CVE-2010-0986P3HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-0986 [HIGH] CWE-787 CVE-2010-0986: Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remot Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.
nvd
CVE-2009-3463P3CRITICALCVSS 9.3≤ 11.5.1.601v1.0+12 more2009-11-04
CVE-2009-3463 [CRITICAL] CWE-119 CVE-2009-3463: Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arb Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.
nvd
CVE-2013-1386P3CRITICALCVSS 10.0≤ 12.0.0.112v1.0+51 more2013-04-10
CVE-2013-1386 [CRITICAL] CVE-2013-1386: Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-1384.
nvd
Adobe Shockwave Player vulnerabilities | cvebase