Vulnerabilities (CVE)

Filtered by vendor Adobe Subscribe
Filtered by product Shockwave Player
Total 174 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-3086 1 Adobe 1 Shockwave Player 2025-04-20 10.0 HIGH 9.8 CRITICAL
Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2017-2983 1 Adobe 1 Shockwave Player 2025-04-20 6.8 MEDIUM 7.8 HIGH
Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.
CVE-2015-7649 1 Adobe 1 Shockwave Player 2025-04-12 10.0 HIGH N/A
Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-5121 1 Adobe 1 Shockwave Player 2025-04-12 10.0 HIGH N/A
Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5120.
CVE-2015-6681 1 Adobe 1 Shockwave Player 2025-04-12 10.0 HIGH N/A
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680.
CVE-2015-5120 1 Adobe 1 Shockwave Player 2025-04-12 10.0 HIGH N/A
Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5121.
CVE-2015-6680 1 Adobe 1 Shockwave Player 2025-04-12 10.0 HIGH N/A
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681.
CVE-2014-0505 1 Adobe 1 Shockwave Player 2025-04-12 10.0 HIGH N/A
Adobe Shockwave Player before 12.1.0.150 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2010-2877 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
Adobe Shockwave Player before 11.5.8.612 does not properly validate a count value in a Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie, related to IML32X.dll and DIRAPIX.dll.
CVE-2011-2118 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
The FLV ASSET Xtra component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors, related to an "input validation vulnerability."
CVE-2011-2127 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2114, CVE-2011-2117, CVE-2011-2124, and CVE-2011-2128.
CVE-2011-2423 1 Adobe 1 Shockwave Player 2025-04-11 10.0 HIGH N/A
msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2010-2876 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
Adobe Shockwave Player before 11.5.8.612 does not properly validate values associated with buffer-size calculation for a 0xFFFFFFF8 record in a (1) .dir or (2) .dcr Director movie, which allows remote attackers to cause a denial of service (heap memory corruption) or execute arbitrary code via a crafted movie.
CVE-2010-3653 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value is used as a pointer offset, as exploited in the wild in October 2010. NOTE: some of these details are obtained from third party information.
CVE-2010-2875 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
Integer signedness error in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a length value associated with the tSAC chunk in a Director movie.
CVE-2011-2117 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2114, CVE-2011-2124, CVE-2011-2127, and CVE-2011-2128.
CVE-2011-2420 1 Adobe 1 Shockwave Player 2025-04-11 10.0 HIGH N/A
Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2010-2582 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
An unspecified function in TextXtra.x32 in Adobe Shockwave Player before 11.5.9.615 does not properly reallocate a buffer when processing a DEMX chunk in a Director file, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code.
CVE-2011-2116 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2111 and CVE-2011-2115.
CVE-2010-3655 1 Adobe 1 Shockwave Player 2025-04-11 9.3 HIGH N/A
Stack-based buffer overflow in dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code via unspecified vectors.