Back

CVE-2005-3591

Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.

Published: Nov 16, 2005 Modified: Jun 16, 2026
CWE-20

CVSS Metrics

Affected Products (8)

Vendor Product Version
macromedia flash_player 6.0
macromedia flash_player 6.0.29.0
macromedia flash_player 6.0.40.0
macromedia flash_player 6.0.47.0
macromedia flash_player 6.0.65.0
macromedia flash_player 6.0.79.0
macromedia flash_player 7.0.19.0
macromedia flash_player 7.0_r19

GitHub Security Advisory GHSA-97j6-6mvm-p2r4

Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 10.45%

Top 5% most likely to be exploited

Threat Score 33.1 / 100

Data Sources

NVD EPSS GitHub