Adobe Shockwave Player vulnerabilities

173 known vulnerabilities affecting adobe/shockwave_player.

Total CVEs
173
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL160HIGH10MEDIUM3

Vulnerabilities

Page 8 of 9
CVE-2010-2881CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2881 [CRITICAL] CWE-119 CVE-2010-2881: IML32.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allo IML32.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a malformed file containing an invalid value, as demonstrated by a value at position 0x24C0 of a certain file.
nvd
CVE-2010-2870CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2870 [CRITICAL] CWE-119 CVE-2010-2870: DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a certain chunk s DIRAPIX.dll in Adobe Shockwave Player before 11.5.8.612 does not properly validate a certain chunk size in the mmap chunk in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.
nvd
CVE-2010-2872CRITICALCVSS 9.3≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2872 [CRITICAL] CWE-20 CVE-2010-2872: Adobe Shockwave Player before 11.5.8.612 does not properly validate an offset value in the pami RIFF Adobe Shockwave Player before 11.5.8.612 does not properly validate an offset value in the pami RIFF chunk in a Director movie, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted movie.
nvd
CVE-2010-2865MEDIUMCVSS 5.0≤ 11.5.7.609v1.0+38 more2010-08-26
CVE-2010-2865 [MEDIUM] CVE-2010-2865: Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows attackers to cause a de Unspecified vulnerability in Adobe Shockwave Player before 11.5.8.612 allows attackers to cause a denial of service via unknown vectors.
nvd
CVE-2010-1292CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1292 [CRITICAL] CWE-119 CVE-2010-1292: The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not v The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.
nvd
CVE-2010-1288CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1288 [CRITICAL] CWE-119 CVE-2010-1288: Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitra Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-0128CRITICALCVSS 9.3≤ 11.5.6.6062010-05-13
CVE-2010-0128 [CRITICAL] CWE-787 CVE-2010-0128: Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Directo Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.
nvd
CVE-2010-1284CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1284 [CRITICAL] CWE-119 CVE-2010-1284: Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corru Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
nvd
CVE-2010-1291CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1291 [CRITICAL] CVE-2010-1291: Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corru Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1290.
nvd
CVE-2010-1289CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1289 [CRITICAL] CVE-2010-1289: Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corru Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1290, and CVE-2010-1291.
nvd
CVE-2010-1286CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1286 [CRITICAL] CVE-2010-1286: Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corru Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
nvd
CVE-2010-1287CRITICALCVSS 9.3≤ 11.5.6.606v1.0+14 more2010-05-13
CVE-2010-1287 [CRITICAL] CVE-2010-1287: Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corru Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
nvd
CVE-2010-1290CRITICALCVSS 9.3≤ 11.5.7.6092010-05-13
CVE-2010-1290 [CRITICAL] CVE-2010-1290: Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corru Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1291.
nvd
CVE-2010-0129HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-0129 [HIGH] CWE-190 CVE-2010-0129: Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cau Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.
nvd
CVE-2010-0130HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-0130 [HIGH] CWE-190 CVE-2010-0130: Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.
nvd
CVE-2010-1283HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-1283 [HIGH] CWE-787 CVE-2010-1283: Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) f Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record.
nvd
CVE-2010-1281HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-1281 [HIGH] CWE-787 CVE-2010-1281: iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.
nvd
CVE-2010-0986HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-0986 [HIGH] CWE-787 CVE-2010-0986: Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remot Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.
nvd
CVE-2010-1280HIGHCVSS 8.8PoCfixed in 11.5.7.6092010-05-13
CVE-2010-1280 [HIGH] CWE-787 CVE-2010-1280: Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.
nvd
CVE-2010-0127HIGHCVSS 8.8fixed in 11.5.7.6092010-05-13
CVE-2010-0127 [HIGH] CWE-787 CVE-2010-0127: Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.
nvd