CVE-2009-4003

Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.
References
Link Resource
http://secunia.com/advisories/37888 Vendor Advisory
http://secunia.com/secunia_research/2009-62/ Vendor Advisory
http://secunia.com/secunia_research/2009-63/ Vendor Advisory
http://secunia.com/secunia_research/2010-1/ Vendor Advisory
http://securitytracker.com/id?1023481
http://www.adobe.com/support/security/bulletins/apsb10-03.html Patch Vendor Advisory
http://www.securityfocus.com/archive/1/509053/100/0/threaded
http://www.securityfocus.com/archive/1/509055/100/0/threaded
http://www.securityfocus.com/archive/1/509058/100/0/threaded
http://www.securityfocus.com/bid/37872
http://www.vupen.com/english/advisories/2010/0171 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/55759
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8538
http://secunia.com/advisories/37888 Vendor Advisory
http://secunia.com/secunia_research/2009-62/ Vendor Advisory
http://secunia.com/secunia_research/2009-63/ Vendor Advisory
http://secunia.com/secunia_research/2010-1/ Vendor Advisory
http://securitytracker.com/id?1023481
http://www.adobe.com/support/security/bulletins/apsb10-03.html Patch Vendor Advisory
http://www.securityfocus.com/archive/1/509053/100/0/threaded
http://www.securityfocus.com/archive/1/509055/100/0/threaded
http://www.securityfocus.com/archive/1/509058/100/0/threaded
http://www.securityfocus.com/bid/37872
http://www.vupen.com/english/advisories/2010/0171 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/55759
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8538
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:shockwave_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:1.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:2.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:3.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:4.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:5.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:6.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:9:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:10.1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.0.0.456:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.0.595:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.0.596:*:*:*:*:*:*:*
cpe:2.3:a:adobe:shockwave_player:11.5.1.601:*:*:*:*:*:*:*

History

21 Nov 2024, 01:08

Type Values Removed Values Added
References () http://secunia.com/advisories/37888 - Vendor Advisory () http://secunia.com/advisories/37888 - Vendor Advisory
References () http://secunia.com/secunia_research/2009-62/ - Vendor Advisory () http://secunia.com/secunia_research/2009-62/ - Vendor Advisory
References () http://secunia.com/secunia_research/2009-63/ - Vendor Advisory () http://secunia.com/secunia_research/2009-63/ - Vendor Advisory
References () http://secunia.com/secunia_research/2010-1/ - Vendor Advisory () http://secunia.com/secunia_research/2010-1/ - Vendor Advisory
References () http://securitytracker.com/id?1023481 - () http://securitytracker.com/id?1023481 -
References () http://www.adobe.com/support/security/bulletins/apsb10-03.html - Patch, Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb10-03.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/509053/100/0/threaded - () http://www.securityfocus.com/archive/1/509053/100/0/threaded -
References () http://www.securityfocus.com/archive/1/509055/100/0/threaded - () http://www.securityfocus.com/archive/1/509055/100/0/threaded -
References () http://www.securityfocus.com/archive/1/509058/100/0/threaded - () http://www.securityfocus.com/archive/1/509058/100/0/threaded -
References () http://www.securityfocus.com/bid/37872 - () http://www.securityfocus.com/bid/37872 -
References () http://www.vupen.com/english/advisories/2010/0171 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/0171 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/55759 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/55759 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8538 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8538 -

Information

Published : 2010-01-21 19:30

Updated : 2024-11-21 01:08


NVD link : CVE-2009-4003

Mitre link : CVE-2009-4003

CVE.ORG link : CVE-2009-4003


JSON object : View

Products Affected

adobe

  • shockwave_player
CWE
CWE-189

Numeric Errors