7 results (0.009 seconds)

CVSS: 7.5EPSS: 92%CPEs: 1EXPL: 1

Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885. Múltiples desbordamientos de búfer basado en pila en un control ActiveX en SwDir.dll 10.1.4.20 en Macromedia Shockwave permite a atacantes remotos provocar denegación de servicio (caida de Internet Explorer 7) y posiblemente ejecutar código de su elección a través de valores característicos de (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, o (6) DrawProgress, vectores diferentes que CVE-2006-6885. • https://www.exploit-db.com/exploits/3421 http://osvdb.org/36005 http://www.securityfocus.com/bid/22842 •

CVSS: 4.3EPSS: 15%CPEs: 1EXPL: 1

An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute. Un control ActiveX en SwDir.dll en Macromedia Shockwave 10 permite a un atacante remoto provocar denegación de servicio (caida de Internet Explorer 7) a través de una cadena en el atributo swURL. • https://www.exploit-db.com/exploits/3042 http://www.securityfocus.com/bid/22067 https://exchange.xforce.ibmcloud.com/vulnerabilities/31160 •

CVSS: 5.0EPSS: 0%CPEs: 4EXPL: 1

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file). Macromedia Flash Plugin anteriores a 6.0.47 permite a atacantes remotos saltarse las restricciones de mismo dominio y leer ficheros arbitrarios mediante Una redirección HTTP Una base "file://" en un documento web una URL relativa de una archivo web (fichero.mht) • http://online.securityfocus.com/archive/1/286625 http://www.iss.net/security_center/static/9797.php http://www.macromedia.com/v1/handlers/index.cfm?ID=23294 http://www.securityfocus.com/bid/5429 https://access.redhat.com/security/cve/CVE-2002-1467 https://bugzilla.redhat.com/show_bug.cgi?id=1616916 •

CVSS: 7.5EPSS: 7%CPEs: 1EXPL: 0

The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length. • http://marc.info/?l=bugtraq&m=103072708329280&w=2 http://www.iss.net/security_center/static/9798.php http://www.macromedia.com/v1/handlers/index.cfm?ID=23293 http://www.redhat.com/support/errata/RHSA-2003-026.html http://www.redhat.com/support/errata/RHSA-2003-027.html http://www.securityfocus.com/bid/5430 https://access.redhat.com/security/cve/CVE-2002-0846 https://bugzilla.redhat.com/show_bug.cgi?id=1616826 •

CVSS: 7.6EPSS: 0%CPEs: 1EXPL: 0

Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file. • http://archives.neohapsis.com/archives/bugtraq/2000-12/0491.html https://exchange.xforce.ibmcloud.com/vulnerabilities/5826 •