CVE-2008-2641
Unspecified vulnerability in Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to an "input…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to an "input validation issue in a JavaScript method."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 23.85% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- adobe/acrobat 3d · adobe/acrobat reader
- Source
- cve@mitre.org
References
- http://isc.sans.org/diary.html?storyid=4616
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html
- http://secunia.com/advisories/30832Patch, Vendor Advisory
- http://secunia.com/advisories/31136
- http://secunia.com/advisories/31339
- http://secunia.com/advisories/31352
- http://secunia.com/advisories/31428
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-240106-1
- http://www.adobe.com/support/security/bulletins/apsb08-15.htmlPatch
- http://www.gentoo.org/security/en/glsa/glsa-200808-10.xml
- http://www.kb.cert.org/vuls/id/788019US Government Resource
- http://www.redhat.com/support/errata/RHSA-2008-0641.html
- http://www.securityfocus.com/bid/29908Patch
- http://www.securitytracker.com/id?1020352
- http://www.vupen.com/english/advisories/2008/1906
- http://www.vupen.com/english/advisories/2008/2289
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43307
- http://isc.sans.org/diary.html?storyid=4616
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html
- http://secunia.com/advisories/30832Patch, Vendor Advisory
- http://secunia.com/advisories/31136
- http://secunia.com/advisories/31339
- http://secunia.com/advisories/31352
- http://secunia.com/advisories/31428
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-240106-1
- http://www.adobe.com/support/security/bulletins/apsb08-15.htmlPatch
- http://www.gentoo.org/security/en/glsa/glsa-200808-10.xml
- http://www.kb.cert.org/vuls/id/788019US Government Resource
- http://www.redhat.com/support/errata/RHSA-2008-0641.html
- http://www.securityfocus.com/bid/29908Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.