Vulnerability Report

CVE-2005-2628

RCE

Title: Macromedia Flash SWF out-of-bounds function pointer execution

RCE

Proof Of Concept

No public PoC currently indexed for CVE-2005-2628.

CWE Category NVD-CWE-noinfo
Published Date Nov 05, 2005
Modified Date Jun 16, 2026
Exploit Status Not Found
Score 5.1 CVSS v2.0
Exploit Probability (EPSS)
6.76%

Vulnerability Summary

CVE-2005-2628: Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.

Impacted Vendors

Reference Links

http://lists.apple.com/archives/security-announce/2006/May/msg00003.html http://secunia.com/advisories/17430 http://secunia.com/advisories/17437/ http://secunia.com/advisories/17481 http://secunia.com/advisories/17626/ http://secunia.com/advisories/17738 http://secunia.com/advisories/20045 http://secunia.com/advisories/20077 http://securitytracker.com/id?1015156 http://www.gentoo.org/security/en/glsa/glsa-200511-21.xml http://www.kb.cert.org/vuls/id/146284 http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html http://www.novell.com/linux/security/advisories/2005_27_sr.html http://www.osvdb.org/18825 http://www.redhat.com/support/errata/RHSA-2005-835.html http://www.securityfocus.com/archive/1/415789/30/0/threaded http://www.securityfocus.com/bid/15332 http://www.securityfocus.com/bid/17951 http://www.us-cert.gov/cas/techalerts/TA06-129A.html http://www.us-cert.gov/cas/techalerts/TA06-132A.html http://www.vupen.com/english/advisories/2005/2317 http://www.vupen.com/english/advisories/2006/1744 http://www.vupen.com/english/advisories/2006/1779 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-020 https://exchange.xforce.ibmcloud.com/vulnerabilities/22959 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1557 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1987 http://lists.apple.com/archives/security-announce/2006/May/msg00003.html http://secunia.com/advisories/17430 http://secunia.com/advisories/17437/ http://secunia.com/advisories/17481 http://secunia.com/advisories/17626/ http://secunia.com/advisories/17738 http://secunia.com/advisories/20045 http://secunia.com/advisories/20077 http://securitytracker.com/id?1015156 http://www.gentoo.org/security/en/glsa/glsa-200511-21.xml http://www.kb.cert.org/vuls/id/146284 http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html http://www.novell.com/linux/security/advisories/2005_27_sr.html http://www.osvdb.org/18825 http://www.redhat.com/support/errata/RHSA-2005-835.html http://www.securityfocus.com/archive/1/415789/30/0/threaded http://www.securityfocus.com/bid/15332 http://www.securityfocus.com/bid/17951 http://www.us-cert.gov/cas/techalerts/TA06-129A.html http://www.us-cert.gov/cas/techalerts/TA06-132A.html http://www.vupen.com/english/advisories/2005/2317 http://www.vupen.com/english/advisories/2006/1744 http://www.vupen.com/english/advisories/2006/1779 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-020 https://exchange.xforce.ibmcloud.com/vulnerabilities/22959 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1557 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1987
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
5.1
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:H/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2005-2628 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.