Описание
Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.
Ссылки
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- PatchVendor Advisory
- Broken Link
- Broken LinkVDB Entry
- Broken LinkVDB Entry
- Broken LinkVendor Advisory
- Tool Signature
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- PatchVendor Advisory
- Broken Link
- Broken LinkVDB Entry
- Broken LinkVDB Entry
- Broken LinkVendor Advisory
- Tool Signature
Уязвимые конфигурации
Конфигурация 1Версия до 11.5.7.609 (исключая)
cpe:2.3:a:adobe:director:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 11.5.6.606 (включая)
Одновременно
cpe:2.3:a:adobe:shockwave_player:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.08216
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-787
Связанные уязвимости
github
почти 4 года назад
Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.
EPSS
Процентиль: 92%
0.08216
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-787