← All CVEs

CVE-2005-3591

high · 7.5

Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.

7.5
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2005-11-16
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
macromediaflash_player6.0
macromediaflash_player6.0.29.0
macromediaflash_player6.0.40.0
macromediaflash_player6.0.47.0
macromediaflash_player6.0.65.0
macromediaflash_player6.0.79.0
macromediaflash_player7.0.19.0
macromediaflash_player7.0_r19

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-3591