CVE-2009-4003

Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
adobeshockwave_player
𝑥
≤ 11.5.2.602
adobeshockwave_player
1.0
adobeshockwave_player
2.0
adobeshockwave_player
3.0
adobeshockwave_player
4.0
adobeshockwave_player
5.0
adobeshockwave_player
6.0
adobeshockwave_player
8.0
adobeshockwave_player
8.5.1
adobeshockwave_player
10.1.0.11
adobeshockwave_player
11.0.0.456
adobeshockwave_player
11.5.0.595
adobeshockwave_player
11.5.0.596
adobeshockwave_player
11.5.1.601
𝑥
= Vulnerable software versions
Common Weakness Enumeration