cbcvebase.

Adobe Shockwave Player vulnerabilities

173 known vulnerabilities affecting adobe/shockwave_player.

Total CVEs
173
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL160HIGH10MEDIUM3

Vulnerabilities

Page 6 of 9
CVE-2013-1384P3CRITICALCVSS 10.0≤ 12.0.0.112v1.0+51 more2013-04-10
CVE-2013-1384 [CRITICAL] CVE-2013-1384: Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-1386.
nvd
CVE-2015-5120P3CRITICALCVSS 10.0≤ 12.1.8.1582015-07-14
CVE-2015-5120 [CRITICAL] CWE-119 CVE-2015-5120: Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5121.
nvd
CVE-2015-5121P3CRITICALCVSS 10.0≤ 12.1.8.1582015-07-14
CVE-2015-5121 [CRITICAL] CVE-2015-5121: Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5120.
nvd
CVE-2010-0129P3HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-0129 [HIGH] CWE-190 CVE-2010-0129: Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cau Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.
nvd
CVE-2010-2581P3CRITICALCVSS 9.3≤ 11.5.8.612v1.0+39 more2010-10-29
CVE-2010-2581 [CRITICAL] CWE-119 CVE-2010-2581: dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director file containing a crafted pamm chunk with an invalid (1) size and (2) number of sub-chunks, a different vulnerability than CVE-2010-4084, CVE-2010-4085, CVE-2010-4086, and CVE-2010-40
nvd
CVE-2013-0635P3CRITICALCVSS 10.0≤ 11.6.8.638v1.0+49 more2013-02-13
CVE-2013-0635 [CRITICAL] CWE-119 CVE-2013-0635: Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2013-3348P3CRITICALCVSS 10.0≤ 12.0.2.122v1.0+52 more2013-07-10
CVE-2013-3348 [CRITICAL] CWE-119 CVE-2013-3348: Adobe Shockwave Player before 12.0.3.133 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.0.3.133 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-7649P3CRITICALCVSS 10.0≤ 12.2.0.1622015-10-28
CVE-2015-7649 [CRITICAL] CWE-119 CVE-2015-7649: Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2010-2867P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2867 [CRITICAL] CWE-119 CVE-2010-2867: DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly handle a certain return va DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly handle a certain return value associated with the rcsL chunk in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie, related to a "pointer offset vulnerability."
nvd
CVE-2010-2874P3CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-09-07
CVE-2010-2874 [CRITICAL] CWE-399 CVE-2010-2874: Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to exe Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption. NOTE: due to conflicting information and use of the same CVE identifier by the vendor, ZDI, and TippingPoint, it is not clear whether this issue is related to use of an uninitiali
nvd
CVE-2010-2587P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2010-2587 [CRITICAL] CWE-119 CVE-2010-2587: The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitr The dirapi.dll module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2588 and CVE-2010-4188.
nvd
CVE-2011-2122P3CRITICALCVSS 9.3≤ 11.5.9.620v1.0+41 more2011-06-16
CVE-2011-2122 [CRITICAL] CVE-2011-2122: Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to rcsL substructures, a different vulnerability than CVE-2011-0317, CVE-2011-0318, CVE-2011-0319, CVE-2011-0320, CVE-2011-0335, and CVE-2011-2119.
nvd
CVE-2011-2421P3CRITICALCVSS 9.3≤ 11.6.0.626v1.0+42 more2011-08-11
CVE-2011-2421 [CRITICAL] CWE-119 CVE-2011-2421: Dirapi.dll in Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or Dirapi.dll in Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir media file.
nvd
CVE-2010-4087P3CRITICALCVSS 9.3≤ 11.5.8.612v1.0+39 more2010-10-29
CVE-2010-4087 [CRITICAL] CWE-119 CVE-2010-4087: IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file with a crafted mmap record containing an invalid length of a VSWV entry, a different vulnerability than CVE-2010-4089.
nvd
CVE-2010-4089P3CRITICALCVSS 9.3≤ 11.5.8.612v1.0+39 more2010-10-29
CVE-2010-4089 [CRITICAL] CVE-2010-4089: IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file containing "duplicated LCSM entries in mmap record," a different vulnerability than CVE-2010-4087.
nvd
CVE-2011-0556P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2011-0556 [CRITICAL] CWE-119 CVE-2011-0556: The Font Xtra.x32 module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arb The Font Xtra.x32 module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PFR1 chunk that leads to an unexpected sign extension and an invalid pointer dereference, a different vulnerability than CVE-2011-0569.
nvd
CVE-2009-3466P3CRITICALCVSS 9.3≤ 11.5.1.601v1.0+12 more2009-11-04
CVE-2009-3466 [CRITICAL] CWE-399 CVE-2009-3466: Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a cra Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an "invalid string length vulnerability." NOTE: some of these details are obtained from third party information.
nvd
CVE-2010-4189P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2010-4189 [CRITICAL] CWE-119 CVE-2010-4189: The IML32 module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary c The IML32 module in Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie containing a GIF image with a crafted global color table size value, which causes an out-of-range pointer offset.
nvd
CVE-2010-4187P3CRITICALCVSS 9.3≤ 11.5.9.615v1.0+40 more2011-02-10
CVE-2010-4187 [CRITICAL] CVE-2010-4187: Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denia Adobe Shockwave Player before 11.5.9.620 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed chunk in a Director file, a different vulnerability than CVE-2011-0555, CVE-2010-4093, CVE-2010-4190, CVE-2010-4191, CVE-2010-4192, and CVE-2010-4306.
nvd
CVE-2010-4088P3CRITICALCVSS 9.3≤ 11.5.8.612v1.0+39 more2010-10-29
CVE-2010-4088 [CRITICAL] CVE-2010-4088: dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file with "duplicated references to the same KEY* chunk," a different vulnerability than CVE-2010-2581, CVE-2010-4084, CVE-2010-4085, and CVE-2010-4086.
nvd
Adobe Shockwave Player vulnerabilities | cvebase