VulnerabilityModified
CVE-2017-11301
An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.
MEDIUM 5.3EPSS 3.22%
Does this matter?
Lower severity and a low EPSS score (3.22%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 3.22% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- adobe/digital editions
- Source
- psirt@adobe.com
References
- http://www.securityfocus.com/bid/101839Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039798Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.htmlVendor Advisory
- http://www.securityfocus.com/bid/101839Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039798Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.