📦

director

Vendor: macromedia

Actively Exploited 0 CISA KEV List
PoC / Exploits 5 Code Available
Total RCEs 2 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 4.14% Exploit Prob.
Latest CVE CVE-2025-46068 Jan 12

Security Vulnerability Index

Page 1 / 1
8.8 CVSS

An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism

EPSS: 0.46%
8.2 CVSS

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file

EPSS: 0.26%
9.9 CVSS

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

EPSS: 0.29%
7.7 CVSS
CVE-2019-10716
Exploit Found

An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /integrations.json JSON REST API request.

EPSS: 4.10%
5.4 CVSS

There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Sequences, and Actors pages.

EPSS: 0.52%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in Blue Coat Director before 5.5.2.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving the HTTP TRACE method.

EPSS: 0.94%
9.3 CVSS

Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.

EPSS: 4.99%
7.8 CVSS

Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a parameter.

EPSS: 1.87%
6.8 CVSS
CVE-2009-0880
Exploit Found

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.

EPSS: 31.60%
5.0 CVSS
CVE-2009-0879
Exploit Found

The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.

EPSS: 8.22%