CVE detail
CVE-2009-3658 — CVE-2009-3658
Published 2009-10-09 · Modified 2026-06-16 · Vendor aol · Product superbuddy_activex_control · Source nvd
HIGH
severity
CVSS-derived band
0.0890
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References