CVE-2009-3463: Buffer Overflow
Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3463?
CVE-2009-3463 has been classified with a critical severity level due to its potential to allow remote code execution.
How do I fix CVE-2009-3463?
To fix CVE-2009-3463, update to the latest version of Adobe Shockwave Player, specifically version 11.5.2.602 or later.
What software versions are affected by CVE-2009-3463?
Adobe Shockwave Player versions prior to 11.5.2.602, including earlier versions like 5.0, 4.0, and 8.5.1, are affected by CVE-2009-3463.
What impact does CVE-2009-3463 have on systems?
CVE-2009-3463 allows attackers to execute arbitrary code on vulnerable systems through crafted Shockwave content.
Is there a workaround for CVE-2009-3463?
Disabling Adobe Shockwave Player or avoiding the use of untrusted Shockwave content can serve as temporary workarounds until the vulnerability is patched.