Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-6271


Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via a Shockwave movie that contains an Xtra URL, as demonstrated by a URL for an outdated Xtra.


Published

2012-12-20T12:02:20.013

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe shockwave_player ≤ 11.6.8.638 Yes
Application adobe shockwave_player 1.0 Yes
Application adobe shockwave_player 2.0 Yes
Application adobe shockwave_player 3.0 Yes
Application adobe shockwave_player 4.0 Yes
Application adobe shockwave_player 5.0 Yes
Application adobe shockwave_player 6.0 Yes
Application adobe shockwave_player 8.0 Yes
Application adobe shockwave_player 8.0.196 Yes
Application adobe shockwave_player 8.0.196a Yes
Application adobe shockwave_player 8.0.204 Yes
Application adobe shockwave_player 8.0.205 Yes
Application adobe shockwave_player 8.5.1 Yes
Application adobe shockwave_player 8.5.1.100 Yes
Application adobe shockwave_player 8.5.1.103 Yes
Application adobe shockwave_player 8.5.1.105 Yes
Application adobe shockwave_player 8.5.1.106 Yes
Application adobe shockwave_player 8.5.321 Yes
Application adobe shockwave_player 8.5.323 Yes
Application adobe shockwave_player 8.5.324 Yes
Application adobe shockwave_player 8.5.325 Yes
Application adobe shockwave_player 9.0.383 Yes
Application adobe shockwave_player 9.0.432 Yes
Application adobe shockwave_player 10.0.0.210 Yes
Application adobe shockwave_player 10.0.1.004 Yes
Application adobe shockwave_player 10.1.0.11 Yes
Application adobe shockwave_player 10.1.0.011 Yes
Application adobe shockwave_player 10.1.1.016 Yes
Application adobe shockwave_player 10.1.4.020 Yes
Application adobe shockwave_player 10.2.0.021 Yes
Application adobe shockwave_player 10.2.0.022 Yes
Application adobe shockwave_player 10.2.0.023 Yes
Application adobe shockwave_player 11.0.0.456 Yes
Application adobe shockwave_player 11.0.3.471 Yes
Application adobe shockwave_player 11.5.0.595 Yes
Application adobe shockwave_player 11.5.0.596 Yes
Application adobe shockwave_player 11.5.1.601 Yes
Application adobe shockwave_player 11.5.2.602 Yes
Application adobe shockwave_player 11.5.6.606 Yes
Application adobe shockwave_player 11.5.7.609 Yes
Application adobe shockwave_player 11.5.8.612 Yes
Application adobe shockwave_player 11.5.9.615 Yes
Application adobe shockwave_player 11.5.9.620 Yes
Application adobe shockwave_player 11.5.10.620 Yes
Application adobe shockwave_player 11.6.0.626 Yes
Application adobe shockwave_player 11.6.1.629 Yes
Application adobe shockwave_player 11.6.3.633 Yes
Application adobe shockwave_player 11.6.4.634 Yes
Application adobe shockwave_player 11.6.5.635 Yes
Application adobe shockwave_player 11.6.6.636 Yes
Application adobe shockwave_player 11.6.7.637 Yes

References