📦

shockwave

Vendor: macromedia

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 0 Remote Access
Total CVEs 7 Total Indexed
Avg. EPSS 11.80% Exploit Prob.
Latest CVE CVE-2017-11294 Dec 09

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

EPSS: 8.84%
7.5 CVSS
CVE-2007-1403
Exploit Found

Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885.

EPSS: 29.22%
4.3 CVSS
CVE-2006-6885
Exploit Found

An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute.

EPSS: 7.23%
5.0 CVSS

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).

EPSS: 1.91%