AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-4003

HIGH · CVSS 9.3 EPSS 7.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-01-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-4003
Severity
HIGH
CVSS
9.3
EPSS
7.39%

Original NVD Description

Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.