Shockwave Player
Vendor:
First CVE: Dec 31, 2005 · Active for 20 years
174
Total CVEs
More Total CVEs than 99% of tracked products
14.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
9.4
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Shockwave Player over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
May 23, 2019
2,619 days ago
CVE Severity & Scoring
Shockwave Player174 CVEs
94%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (0.6%)
Network18 (10.3%)
Unknown155 (89.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (10.9%)
High0 (0.0%)
Unknown155 (89.1%)
User Interaction
None8 (4.6%)
Unknown155 (89.1%)
Required11 (6.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (10.9%)
Unknown155 (89.1%)
Top CVEs
Signals from CVEs in this product scope (174 CVEs).
174 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3653HIGH The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via | Oct 26, 2010 | 9.3 | 84 | NO | YES |
CVE-2007-5941HIGH Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a lon | Nov 14, 2007 | 10.0 | 56 | NO | YES |
CVE-2010-1280HIGH Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, | May 13, 2010 | 8.8 | 47 | NO | YES |
CVE-2010-2866HIGH Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitr | Aug 26, 2010 | 9.3 | 43 | NO | YES |
CVE-2009-3244HIGH Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execu | Sep 18, 2009 | 9.3 | 43 | NO | YES |
CVE-2012-2031HIGH Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerabil | May 9, 2012 | 10.0 | 40 | NO | NO |
CVE-2019-7100CRITICAL Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | May 23, 2019 | 9.8 | 34 | NO | NO |
CVE-2012-4172HIGH Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-20 | Oct 23, 2012 | 10.0 | 34 | NO | NO |
CVE-2012-2030HIGH Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerabil | May 9, 2012 | 10.0 | 34 | NO | NO |
CVE-2019-7103CRITICAL Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | May 23, 2019 | 9.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (174 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
2.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (174 CVEs).
Media Mentions
Signals from CVEs in this product scope (174 CVEs).
Top CNAs Publishing CVEs For Shockwave Player
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.432 | 127 | 9.5 | 5.9% | 0 | 3 |
| 9.0.383 | 127 | 9.5 | 5.9% | 0 | 3 |
| 9 | 132 | 9.4 | 5.2% | 0 | 2 |
| 8.5.325 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.324 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.323 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.321 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.1.106 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.1.105 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.1.103 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.1.100 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.5.1 | 143 | 9.5 | 5.9% | 0 | 3 |
| 8.0.205 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.0.204 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.0.196a | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.0.196 | 127 | 9.5 | 5.9% | 0 | 3 |
| 8.0 | 143 | 9.5 | 5.9% | 0 | 3 |
| 6.0 | 143 | 9.5 | 5.9% | 0 | 3 |
| 5.0 | 143 | 9.5 | 5.9% | 0 | 3 |
| 4.0 | 143 | 9.5 | 5.9% | 0 | 3 |