CVE-2008-5363
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers…
Does this matter?
Lower severity and a low EPSS score (3.72%). Track it; it rarely justifies an emergency change on its own.
Description
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 3.72% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- adobe/air · adobe/flash player
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatch, Vendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party Advisory, VDB Entry
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatch, Vendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.