CVE Vulnerabilities

CVE-2009-4003

Published: Jan 21, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.

Affected Software

NameVendorStart VersionEnd Version
Shockwave_playerAdobe*11.5.2.602 (including)
Shockwave_playerAdobe1.0 (including)1.0 (including)
Shockwave_playerAdobe2.0 (including)2.0 (including)
Shockwave_playerAdobe3.0 (including)3.0 (including)
Shockwave_playerAdobe4.0 (including)4.0 (including)
Shockwave_playerAdobe5.0 (including)5.0 (including)
Shockwave_playerAdobe6.0 (including)6.0 (including)
Shockwave_playerAdobe8.0 (including)8.0 (including)
Shockwave_playerAdobe8.5.1 (including)8.5.1 (including)
Shockwave_playerAdobe9 (including)9 (including)
Shockwave_playerAdobe10.1.0.11 (including)10.1.0.11 (including)
Shockwave_playerAdobe11.0.0.456 (including)11.0.0.456 (including)
Shockwave_playerAdobe11.5.0.595 (including)11.5.0.595 (including)
Shockwave_playerAdobe11.5.0.596 (including)11.5.0.596 (including)
Shockwave_playerAdobe11.5.1.601 (including)11.5.1.601 (including)

References