VulnerabilityModified
CVE-2017-11273
Adobe Digital Editions parses crafted XML files in an unsafe manner, which could lead to sensitive information disclosure.
MEDIUM 5.5EPSS 4.38%
Does this matter?
Lower severity and a low EPSS score (4.38%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. Adobe Digital Editions parses crafted XML files in an unsafe manner, which could lead to sensitive information disclosure.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 4.38% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- adobe/digital editions
- Source
- psirt@adobe.com
References
- http://www.securityfocus.com/bid/101839Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039798Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.htmlVendor Advisory
- http://www.securityfocus.com/bid/101839Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039798Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.