VendorsAdobeshockwave_playerany version
Vulnerabilities

Adobe Shockwave Player any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

172CVEs
CVE-2007-5941
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method.
Published 2007-11-14 · Modified
10.01 PoCEPSS 0.323
CVE-2012-2031
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2032, and CVE-2012-2033.
Published 2012-05-09 · Modified
10.0EPSS 0.181
CVE-2012-4172
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.
Published 2012-10-23 · Modified
10.0EPSS 0.097
CVE-2012-4173
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.
Published 2012-10-23 · Modified
10.0EPSS 0.096
CVE-2012-4175
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-5273.
Published 2012-10-23 · Modified
10.0EPSS 0.096
CVE-2012-4174
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4175, and CVE-2012-5273.
Published 2012-10-23 · Modified
10.0EPSS 0.096
CVE-2013-0636
Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code via unspecified vectors.
Published 2013-02-13 · Modified
10.0EPSS 0.093
CVE-2012-5273
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175.
Published 2012-10-23 · Modified
10.0EPSS 0.086
CVE-2012-4176
Array index error in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors.
Published 2012-10-23 · Modified
10.0EPSS 0.073
CVE-2017-3086
Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2017-06-20 · Modified
10.0EPSS 0.069
CVE-2011-2423
msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2011-08-11 · Modified
10.0EPSS 0.065
CVE-2012-2029
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2030, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.
Published 2012-05-09 · Modified
10.0EPSS 0.063
CVE-2012-2030
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.
Published 2012-05-09 · Modified
10.0EPSS 0.062
CVE-2012-0758
Heap-based buffer overflow in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code via unspecified vectors.
Published 2012-02-15 · Modified
10.0EPSS 0.060
CVE-2014-0501
Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0500.
Published 2014-02-12 · Modified
10.0EPSS 0.060
CVE-2013-1383
Buffer overflow in Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code via unspecified vectors.
Published 2013-04-10 · Modified
10.0EPSS 0.060
CVE-2014-0500
Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0501.
Published 2014-02-12 · Modified
10.0EPSS 0.059
CVE-2012-2032
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2033.
Published 2012-05-09 · Modified
10.0EPSS 0.057
CVE-2015-6681
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680.
Published 2015-09-09 · Modified
10.0EPSS 0.056
CVE-2013-0635
Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2013-02-13 · Modified
10.0EPSS 0.053
CVE-2012-2033
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2032.
Published 2012-05-09 · Modified
10.0EPSS 0.053
CVE-2011-2419
IML32.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2011-08-11 · Modified
10.0EPSS 0.053
CVE-2019-7103
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-23 · Modified
10.0EPSS 0.052
CVE-2019-7100
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-23 · Modified
10.0EPSS 0.052
CVE-2019-7098
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-23 · Modified
10.0EPSS 0.052
CVE-2019-7099
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-23 · Modified
10.0EPSS 0.052
CVE-2015-6680
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681.
Published 2015-09-09 · Modified
10.0EPSS 0.051
CVE-2019-7104
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-23 · Modified
10.0EPSS 0.051
CVE-2012-0764
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0766.
Published 2012-02-15 · Modified
10.0EPSS 0.050
CVE-2011-2420
Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2011-08-11 · Modified
10.0EPSS 0.049
CVE-2011-2422
Textra.x32 in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2011-08-11 · Modified
10.0EPSS 0.049
CVE-2014-0505
Adobe Shockwave Player before 12.1.0.150 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2014-03-14 · Modified
10.0EPSS 0.048
CVE-2013-3360
Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3359.
Published 2013-09-11 · Modified
10.0EPSS 0.046
CVE-2012-0761
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
Published 2012-02-15 · Modified
10.0EPSS 0.046
CVE-2012-0762
The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.
Published 2012-02-15 · Modified
10.0EPSS 0.046
CVE-2010-2863
Adobe Shockwave Player before 11.5.8.612 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
Published 2010-08-26 · Modified
10.0EPSS 0.044
CVE-2013-1385
Adobe Shockwave Player before 12.0.2.122 does not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
Published 2013-04-10 · Modified
10.0EPSS 0.043
CVE-2010-4308
Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4309.
Published 2011-08-11 · Modified
10.0EPSS 0.042
CVE-2010-4309
Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4308.
Published 2011-08-11 · Modified
10.0EPSS 0.042
CVE-2019-7102
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-23 · Modified
10.0EPSS 0.041
1 / 5Next →