CVE-2011-2123

Description

Integer overflow in the Shockwave 3D Asset x32 component in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code via a crafted subrecord in a DEMX chunk, which triggers a heap-based buffer overflow.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
12.903

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Adobe Shockwave Player 1.0Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.0.0.210Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.0.1.004Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.1.0.011Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.1.0.11Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.1.1.016Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.1.4.020Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.2.0.021Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.2.0.022Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 10.2.0.023Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.0.0.456Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.0.3.471Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.0.595Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.0.596Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.1.601Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.2.602Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.6.606Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.7.609Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.8.612Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.9.615Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 11.5.9.620Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 2.0Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 3.0Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 4.0Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 5.0Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 6.0Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.0Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.0.196Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.0.196aWindows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.0.204Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.0.205Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.1Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.1.100Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.1.103Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.1.105Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.1.106Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.321Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.323Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.324Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 8.5.325Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 9Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 9.0.383Windows
Multiple Vulnerabilities are affected in Adobe Shockwave Player 9.0.432Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)
PATCH-309312Adobe Shockwave Player (12.3.5.205)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234