Vulnerabilities > CVE-2011-2108 - Remote Code Execution vulnerability in Adobe Shockwave Player

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
adobe
critical
nessus

Summary

Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors, related to a "design flaw."

Nessus

  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_SHOCKWAVE_PLAYER_APSB11-17.NASL
    descriptionThe remote Mac OS X host contains a version of Adobe Shockwave Player that is 11.5.9.620 or earlier. It is, therefore, affected by multiple vulnerabilities : - Multiple memory corruption vulnerabilities affect the
    last seen2020-06-01
    modified2020-06-02
    plugin id80176
    published2014-12-22
    reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/80176
    titleAdobe Shockwave Player <= 11.5.9.620 (APSB11-17) (Mac OS X)
  • NASL familyWindows
    NASL idSHOCKWAVE_PLAYER_APSB11-17.NASL
    descriptionThe remote Windows host contains a version of Adobe
    last seen2020-06-01
    modified2020-06-02
    plugin id55142
    published2011-06-15
    reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/55142
    titleShockwave Player < 11.6.0.626 (APSB11-17)