10
CVSSv2

CVE-2014-0505

Published: 14/03/2014 Updated: 14/03/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Shockwave Player prior to 12.1.0.150 allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe shockwave player 12.0.2.122

adobe shockwave player 12.0.4.144

adobe shockwave player 12.0.0.112

adobe shockwave player 12.0.3.133

adobe shockwave player 12.0.6.147

adobe shockwave player 12.0.7.148

adobe shockwave player

Recent Articles

Didn't you know? Today's Patch Thursday! Adobe splats hijack bug in Shockwave Player
The Register • Shaun Nichols in San Francisco • 13 Mar 2014

Update now before someone reverse-engineers this RCE

Adobe has updated its Shockwave Player to close a security hole that could allow hackers to hijack vulnerable Windows and OS X computers. The Photoshop giant said version 12.1.150 will address a flaw that enables an attacker to potentially remotely control a targeted system: a malicious file opened by Shockwave could exploit a memory corruption bug to perform remote code execution. Given the animation player runs in the user's browser, it would be trivial to take a swipe at passing web visitors....