← Vulnerability feed

Vulnerability record · CVE-2009-3587 · published 13 October 2009

CVE-2009-3587: Broadcom anti-virus vulnerability

Broadcom · Anti Virus

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.

9.3 CVSS 2.0 High EPSS 7.6% · top 5.7%
9.3CVSS 2.0 base score
7.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
32Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

32 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3587 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0042Broadcom anti-spyware vulnerabilityMultiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterpr…EPSS 4.3%10.0CVE-2007-2863Broadcom anti-virus for the enterprise vulnerabilityStack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote …EPSS 23%10.0CVE-2005-1693Broadcom etrust antivirus vulnerabilityInteger overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for…EPSS 6.9%9.3CVE-2007-2864CA Anti-Virus engine stack buffer overflow via crafted CAB fileThe Anti-Virus engine in multiple CA (Computer Associates) products before content update 30.6 has a stack-based buffer overflow triggered by a large…EPSS 50%analysed9.0CVE-2007-4620CA Alert Notification Service stack buffer overflow via RPCMultiple stack-based buffer overflows exist in Computer Associates Alert Notification Service (Alert.exe) versions 8.1.586.0, 8.0.450.0, and 7.1.758.…EPSS 52%analysed7.5CVE-2006-3223Broadcom etrust antivirus vulnerabilityFormat string vulnerability in CA Integrated Threat Management (ITM), eTrust Antivirus (eAV), and eTrust PestPatrol (ePP) r8 allows attackers to caus…EPSS 6.7%7.5CVE-2004-0937Archive zip vulnerabilitySophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protecti…EPSS 15%7.5CVE-2004-0932McAfee Anti-Virus Engine DATS driver bypass via malformed compressed fileThe McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files…EPSS 63%analysed

Source: NIST National Vulnerability Database (record CVE-2009-3587), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.