Unrated severityNVD Advisory· Published Apr 6, 2009· Updated Apr 23, 2026
CVE-2009-0909
CVE-2009-0909
Description
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435.
Affected products
4- cpe:2.3:a:vmware:workstation:6.5.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.vmware.com/pipermail/security-announce/2009/000054.htmlnvdPatchVendor Advisory
- seclists.org/fulldisclosure/2009/Apr/0036.htmlnvdPatch
- www.securityfocus.com/bid/34373nvdExploit
- security.gentoo.org/glsa/glsa-201209-25.xmlnvd
- www.securitytracker.com/idnvd
- www.vmware.com/security/advisories/VMSA-2009-0005.htmlnvd
- www.vupen.com/english/advisories/2009/0944nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6251nvd
News mentions
0No linked articles in our index yet.