Shockwave Player

Vendor:

First CVE: Dec 31, 2005 · Active for 20 years

174
Total CVEs
More Total CVEs than 99% of tracked products
14.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
9.4
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Shockwave Player over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
May 23, 2019
2,619 days ago

CVE Severity & Scoring

Shockwave Player174 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (0.6%)
Network18 (10.3%)
Unknown155 (89.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (10.9%)
High0 (0.0%)
Unknown155 (89.1%)
User Interaction
None8 (4.6%)
Unknown155 (89.1%)
Required11 (6.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (10.9%)
Unknown155 (89.1%)

Top CVEs

Signals from CVEs in this product scope (174 CVEs).

174 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via
Oct 26, 20109.384NOYES
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a lon
Nov 14, 200710.056NOYES
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file,
May 13, 20108.847NOYES
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitr
Aug 26, 20109.343NOYES
Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execu
Sep 18, 20099.343NOYES
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerabil
May 9, 201210.040NONO
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
May 23, 20199.834NONO
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-20
Oct 23, 201210.034NONO
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerabil
May 9, 201210.034NONO
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
May 23, 20199.833NONO

Exploit Exposure

Signals from CVEs in this product scope (174 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
2.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (174 CVEs).

Media Mentions

Signals from CVEs in this product scope (174 CVEs).

Top CNAs Publishing CVEs For Shockwave Player

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.4321279.55.9%03
9.0.3831279.55.9%03
91329.45.2%02
8.5.3251279.55.9%03
8.5.3241279.55.9%03
8.5.3231279.55.9%03
8.5.3211279.55.9%03
8.5.1.1061279.55.9%03
8.5.1.1051279.55.9%03
8.5.1.1031279.55.9%03
8.5.1.1001279.55.9%03
8.5.11439.55.9%03
8.0.2051279.55.9%03
8.0.2041279.55.9%03
8.0.196a1279.55.9%03
8.0.1961279.55.9%03
8.01439.55.9%03
6.01439.55.9%03
5.01439.55.9%03
4.01439.55.9%03