CVE-2009-1860
Adobe Shockwave Player Director File Parsing Pointer Overwrite Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content.
Vulnerabilidad sin especificar en Adobe Shockwave Player anterior a v11.5.0.600 permite a atacantes remotos ejecutar código de su elección a través de contenido Shockwave Player 10 manipulado.
This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe's Shockwave Player. User interaction is required in that a user must visit a malicious web site.
The specific flaw exists when the Shockwave player attempts to load a specially crafted Adobe Director File. When a malicious value is used during a memory dereference a possible 4-byte memory overwrite may occur. Exploitation can lead to remote system compromise under the credentials of the currently logged in user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-06-01 CVE Reserved
- 2009-06-24 CVE Published
- 2023-11-11 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/35469 | Vdb Entry | |
http://www.securitytracker.com/id?1022440 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.adobe.com/support/security/bulletins/apsb09-08.html | 2009-07-02 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35544 | 2009-07-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | <= 11.5.0.596 Search vendor "Adobe" for product "Shockwave Player" and version " <= 11.5.0.596" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 1.0 Search vendor "Adobe" for product "Shockwave Player" and version "1.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 2.0 Search vendor "Adobe" for product "Shockwave Player" and version "2.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 3.0 Search vendor "Adobe" for product "Shockwave Player" and version "3.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 4.0 Search vendor "Adobe" for product "Shockwave Player" and version "4.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 5.0 Search vendor "Adobe" for product "Shockwave Player" and version "5.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 6.0 Search vendor "Adobe" for product "Shockwave Player" and version "6.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 8.0 Search vendor "Adobe" for product "Shockwave Player" and version "8.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 8.5.1 Search vendor "Adobe" for product "Shockwave Player" and version "8.5.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 9 Search vendor "Adobe" for product "Shockwave Player" and version "9" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 10.1.0.11 Search vendor "Adobe" for product "Shockwave Player" and version "10.1.0.11" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Shockwave Player Search vendor "Adobe" for product "Shockwave Player" | 11.5.0.595 Search vendor "Adobe" for product "Shockwave Player" and version "11.5.0.595" | - |
Affected
|