CVE-2009-4588
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 32%
from disclosure to weapon0 days
Published on NVDJan 7
1st PoCJul 10
metasploitJul 10
exploitation probability
32%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a different vulnerability than CVE-2009-2386. NOTE: some of these details are obtained from third party information.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/9116unverifiedexploitdbwww.exploit-db.com/exploits/9116unverifiedexploitdbwww.exploit-db.com/exploits/16524unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.