CVE Feed

    Dashboard / CVE / CVE-2009-3587

    CVE-2009-3587

    Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.

    Published:Oct 13, 2009
    Last Modified:Apr 23, 2026
    EPS:Oct 13, 2009
    EPSS Score:0.07394
    CVSS Score:9.3

    Affected Products

    Vendor
    Broadcom
    Product
    Anti-virus
    Vendor
    Broadcom
    Product
    Anti-virus For The Enterprise
    Vendor
    Broadcom
    Product
    Anti-virus Sdk
    Vendor
    Broadcom
    Product
    Common Services
    Vendor
    Broadcom
    Product
    Etrust Antivirus
    Vendor
    Broadcom
    Product
    Etrust Integrated Threat Management
    Vendor
    Broadcom
    Product
    Etrust Intrusion Detection
    Vendor
    Broadcom
    Product
    Etrust Secure Content Manager
    Vendor
    Broadcom
    Product
    Internet Security Suite
    Vendor
    Broadcom
    Product
    Network And Systems Management
    Vendor
    Broadcom
    Product
    Secure Content Manager
    Vendor
    Broadcom
    Product
    Unicenter Network And Systems Management
    Vendor
    Ca
    Product
    Anti-virus
    Vendor
    Ca
    Product
    Anti-virus For The Enterprise
    Vendor
    Ca
    Product
    Anti-virus Gateway
    Vendor
    Ca
    Product
    Anti-virus Plus
    Vendor
    Ca
    Product
    Arcserve Backup
    Vendor
    Ca
    Product
    Arcserve For Windows Client Agent
    Vendor
    Ca
    Product
    Arcserve For Windows Server Component
    Vendor
    Ca
    Product
    Common Services
    Vendor
    Ca
    Product
    Etrust Anti-virus Gateway
    Vendor
    Ca
    Product
    Etrust Anti-virus Sdk
    Vendor
    Ca
    Product
    Etrust Ez Antivirus
    Vendor
    Ca
    Product
    Etrust Intrusion Detection
    Vendor
    Ca
    Product
    Etrust Secure Content Manager
    Vendor
    Ca
    Product
    Gateway Security
    Vendor
    Ca
    Product
    Internet Security Suite 2008
    Vendor
    Ca
    Product
    Internet Security Suite Plus 2008
    Vendor
    Ca
    Product
    Internet Security Suite Plus 2009
    Vendor
    Ca
    Product
    Protection Suites
    Vendor
    Ca
    Product
    Threat Manager
    Vendor
    Ca
    Product
    Threat Manager Total Defense
    Vendor
    Linux
    Product
    Linux Kernel

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High