VYPR

Shockwave Player

by Adobe Inc.

CVEs (175)

  • CVE-2010-3653Oct 26, 2010
    risk 0.09cvss —epss 0.75

    The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value is used as a pointer…

  • CVE-2007-5941Nov 14, 2007
    risk 0.06cvss —epss 0.32

    Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method.

  • CVE-2009-3244Sep 18, 2009
    risk 0.05cvss —epss 0.20

    Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.

  • CVE-2010-2866Aug 26, 2010
    risk 0.04cvss —epss 0.13

    Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a…

  • CVE-2005-3525Dec 31, 2005
    risk 0.02cvss —epss 0.20

    Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters.

  • CVE-2013-0636Feb 13, 2013
    risk 0.01cvss —epss 0.09

    Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code via unspecified vectors.

  • CVE-2012-5273Oct 23, 2012
    risk 0.01cvss —epss 0.09

    Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175.

  • CVE-2012-4176Oct 23, 2012
    risk 0.01cvss —epss 0.07

    Array index error in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors.

  • CVE-2012-4175Oct 23, 2012
    risk 0.01cvss —epss 0.10

    Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-5273.

  • CVE-2012-4174Oct 23, 2012
    risk 0.01cvss —epss 0.10

    Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4175, and CVE-2012-5273.

  • CVE-2012-4173Oct 23, 2012
    risk 0.01cvss —epss 0.10

    Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.

  • CVE-2012-4172Oct 23, 2012
    risk 0.01cvss —epss 0.10

    Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.

  • CVE-2012-2031May 9, 2012
    risk 0.01cvss —epss 0.18

    Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2032, and CVE-2012-2033.

  • CVE-2012-2029May 9, 2012
    risk 0.01cvss —epss 0.06

    Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2030, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.

  • CVE-2011-2423Aug 11, 2011
    risk 0.01cvss —epss 0.06

    msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

  • CVE-2011-2126Jun 16, 2011
    risk 0.01cvss —epss 0.07

    Buffer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

  • CVE-2011-2125Jun 16, 2011
    risk 0.01cvss —epss 0.07

    Buffer overflow in Dirapix.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

  • CVE-2011-2123Jun 16, 2011
    risk 0.01cvss —epss 0.07

    Integer overflow in the Shockwave 3D Asset x32 component in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code via a crafted subrecord in a DEMX chunk, which triggers a heap-based buffer overflow.

  • CVE-2011-2115Jun 16, 2011
    risk 0.01cvss —epss 0.08

    IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted tSAC chunk, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2011-2111 and…

  • CVE-2011-2112Jun 16, 2011
    risk 0.01cvss —epss 0.07

    Multiple buffer overflows in IML32.dll in Adobe Shockwave Player before 11.6.0.626 allow attackers to execute arbitrary code via unspecified vectors.

Page 2 of 9