Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers.
| Software | From | Fixed in |
|---|---|---|
| macromedia / flash_player | 5.0_r50 | 5.0_r50.x |
| macromedia / flash_player | 5.0 | 5.0.x |
| macromedia / flash_player | 6.0.29.0 | 6.0.29.0.x |
| macromedia / flash_player | 6.0 | 6.0.x |
| macromedia / flash_player | 4.0_r12 | 4.0_r12.x |
| macromedia / flash_player | 6.0.47.0 | 6.0.47.0.x |
| macromedia / flash_player | 6.0.40.0 | 6.0.40.0.x |