CVE-2009-2186: Critical severity adobe shockwave player vulnerability
Published Jun 24, 2009
·Updated
Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave Player 11.0.0.465."
Affected Software
11 affected components
Adobe Shockwave Player=5.0
Adobe Shockwave Player=4.0
Adobe Shockwave Player=8.5.1
Adobe Shockwave Player=6.0
Adobe Shockwave Player=10.1.0.11
Adobe Shockwave Player=1.0
Adobe Shockwave Player=2.0
Adobe Shockwave Player=8.0
Adobe Shockwave Player=3.0
Adobe Shockwave Player=9
Adobe Shockwave Player<=11.0.0.456
Remediation
Event History
Jun 24, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2186?
CVE-2009-2186 is classified as a critical vulnerability, allowing remote attackers to execute arbitrary code.
2
What versions of Adobe Shockwave Player are affected by CVE-2009-2186?
CVE-2009-2186 affects multiple versions of Adobe Shockwave Player prior to 11.0.0.465.
3
How do I fix CVE-2009-2186?
To fix CVE-2009-2186, update Adobe Shockwave Player to version 11.0.0.465 or later.
4
Can CVE-2009-2186 be exploited remotely?
Yes, CVE-2009-2186 can be exploited by remote attackers to execute arbitrary code.
5
Is there any relation between CVE-2009-2186 and CVE-2009-1860?
CVE-2009-2186 is a different vulnerability than CVE-2009-1860, despite both affecting Adobe Shockwave Player.