Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.
2005-11-16T07:42:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | macromedia | flash_player | 6.0 | Yes |
| Application | macromedia | flash_player | 6.0.29.0 | Yes |
| Application | macromedia | flash_player | 6.0.40.0 | Yes |
| Application | macromedia | flash_player | 6.0.47.0 | Yes |
| Application | macromedia | flash_player | 6.0.65.0 | Yes |
| Application | macromedia | flash_player | 6.0.79.0 | Yes |
| Application | macromedia | flash_player | 7.0.19.0 | Yes |
| Application | macromedia | flash_player | 7.0_r19 | Yes |