« Volver al listado

CVE-2009-4588

Estado: ModificadaAlta (9.3)—

Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a different vulnerability than CVE-2009-2386. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-4588",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-01-07T18:30:00.887",
  "references": [
    {
      "url": "http://secunia.com/advisories/35764",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.exploit-db.com/exploits/9116",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.shinnai.net/exploits/nsGUdeley3EHfKEV690p.txt",
      "tags": [
        "Exploit",
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51672",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/35764",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.exploit-db.com/exploits/9116",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.shinnai.net/exploits/nsGUdeley3EHfKEV690p.txt",
      "tags": [
        "Exploit",
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51672",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a different vulnerability than CVE-2009-2386.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en memoria dinámica en el control ActiveX WindsPlayerIE.View.1 en WindsPly.ocx v3.5.0.0 Beta, v3.0.0.5, y anteriores en AwingSoft Awakening Web3D Player y Winds3D Viewer permite a atacantes remotos provocar un denegación de servicio (caída de aplicación) o ejecutar código de su elección a través de un valor largo de la propiedad SceneUrl, una vulnerabilidad diferente a CVE-2009-2386. NOTA: algunos detalles han sido obtenidos a partir de información de terceros."
    }
  ],
  "lastModified": "2026-06-16T23:13:58.587",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:awingsoft:awakening_winds3d_player:3.0.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FAC1CE7-5C88-4192-8A48-5F3C1A3B3F64"
            },
            {
              "criteria": "cpe:2.3:a:awingsoft:awakening_winds3d_player:3.5.0.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A73D2E0-7DF7-4E26-BBAA-EE2DC7D59067"
            },
            {
              "criteria": "cpe:2.3:a:awingsoft:awakening_winds3d_viewer:3.0.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E004A43-C33C-47D1-BAB1-174EFED1AE7D"
            },
            {
              "criteria": "cpe:2.3:a:awingsoft:awakening_winds3d_viewer:3.5.0.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1304D733-CE55-4085-82F0-AF1FC5854883"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}