9.3

CVE-2009-3465

Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3464.  NOTE: some of these details are obtained from third party information.

Data is provided by the National Vulnerability Database (NVD)
AdobeShockwave Player Version <= 11.5.1.601
AdobeShockwave Player Version1.0
AdobeShockwave Player Version2.0
AdobeShockwave Player Version3.0
AdobeShockwave Player Version4.0
AdobeShockwave Player Version5.0
AdobeShockwave Player Version6.0
AdobeShockwave Player Version8.0
AdobeShockwave Player Version8.5.1
AdobeShockwave Player Version9
AdobeShockwave Player Version10.1.0.11
AdobeShockwave Player Version11.0.0.456
AdobeShockwave Player Version11.5.0.595
AdobeShockwave Player Version11.5.0.596
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 11.78% 0.93
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.