Unrated severityNVD Advisory· Published Nov 24, 2009· Updated Apr 23, 2026
CVE-2009-3576
CVE-2009-3576
Description
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.
Affected products
2- cpe:2.3:a:autodesk:autodesk_softimage:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autodesk_softimage_xsi:6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.