CVE-2008-5363
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.
La máquina virtual ActionScript v2 en Adobe Flash Player v10.x anteriores a v10.0.12.36 y en v9.x anteriores a v9.0.151.0, y en Adobe AIR anteriores a v1.5, no realizan validación de los caracteres de los elementos durante la recuperación de la estructura de datos del diccionario, permitiendo a atacantes remotos provocar una denegación de servicio (referencia a puntero NULO y parada de la aplicación) mediante un fichero PDF modificado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-12-07 CVE Reserved
- 2008-12-08 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/33390 | Third Party Advisory | |
http://secunia.com/advisories/34226 | Third Party Advisory | |
http://securityreason.com/securityalert/4692 | Third Party Advisory | |
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm | Third Party Advisory | |
http://www.isecpartners.com/advisories/2008-01-flash.txt | Third Party Advisory | |
http://www.securityfocus.com/archive/1/498561/100/0/threaded | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.adobe.com/support/security/bulletins/apsb08-22.html | 2018-11-02 |
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-200903-23.xml | 2018-11-02 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 | 2018-11-02 | |
https://access.redhat.com/security/cve/CVE-2008-5363 | 2008-11-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1618339 | 2008-11-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Air Search vendor "Adobe" for product "Air" | < 1.5 Search vendor "Adobe" for product "Air" and version " < 1.5" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 9.0.16.0 < 9.0.151.0 Search vendor "Adobe" for product "Flash Player" and version " >= 9.0.16.0 < 9.0.151.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 10 < 10.0.12.36 Search vendor "Adobe" for product "Flash Player" and version " >= 10 < 10.0.12.36" | - |
Affected
|