9.3

CVE-2009-3466

Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an "invalid string length vulnerability." NOTE: some of these details are obtained from third party information.

Data is provided by the National Vulnerability Database (NVD)
AdobeShockwave Player Version <= 11.5.1.601
AdobeShockwave Player Version1.0
AdobeShockwave Player Version2.0
AdobeShockwave Player Version3.0
AdobeShockwave Player Version4.0
AdobeShockwave Player Version5.0
AdobeShockwave Player Version6.0
AdobeShockwave Player Version8.0
AdobeShockwave Player Version8.5.1
AdobeShockwave Player Version9
AdobeShockwave Player Version10.1.0.11
AdobeShockwave Player Version11.0.0.456
AdobeShockwave Player Version11.5.0.595
AdobeShockwave Player Version11.5.0.596
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.3% 0.878
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C