Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 3.6% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291. | |
| Modificada | Alta (9.3) | 4.0% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291. | |
| Modificada | Alta (9.3) | 6.4% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka… | |
| Modificada | Alta (8.8) | 6.3% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record. | |
| Modificada | Media (6.5) | 3.0% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted ATOM size in a .dir (aka Director) file. | |
| Modificada | Alta (8.8) | 7.5% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file. | |
| Modificada | Alta (8.8) | 11% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file. | |
| Modificada | Alta (8.8) | 5.1% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file. | |
| Modificada | Alta (8.8) | 7.3% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file. | |
| Modificada | Alta (8.8) | 6.3% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error. | |
| Modificada | Alta (9.3) | 5.0% | — | Adobe DirectorAdobe Shockwave Player | 13/5/2010 | 16/6/2026 | Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation. | |
| Modificada | Alta (8.8) | 5.1% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file. | |
| Modificada | Alta (9.3) | 7.4% | — | Adobe Shockwave Player | 21/1/2010 | 16/6/2026 | Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a… | |
| Modificada | Alta (9.3) | 8.7% | — | Adobe Shockwave Player | 21/1/2010 | 16/6/2026 | Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file. | |
| Modificada | Alta (9.3) | 4.2% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an "invalid string length vulnerability." NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.1% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3464. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.1% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3465. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.1% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 20% | 💥 Exploit | Adobe Shockwave Player | 18/9/2009 | 16/6/2026 | Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value. | |
| Modificada | Alta (9.3) | 4.7% | — | Adobe Shockwave Player | 25/6/2009 | 16/6/2026 | Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave Player 11.0.0.465." | |
| Modificada | Alta (9.3) | 5.6% | — | Adobe Shockwave Player | 25/6/2009 | 16/6/2026 | Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content. | |
| Modificada | Alta (10) | 32% | 💥 Exploit | Adobe Shockwave Player | 14/11/2007 | 16/6/2026 | Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method. | |
| Modificada | Media (5) | 6.2% | — | Adobe Shockwave Player | 8/10/2007 | 16/6/2026 | The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the… | |
| Modificada | Alta (7.5) | 29% | 💥 Exploit | Macromedia Shockwave | 10/3/2007 | 16/6/2026 | Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress… |