4.3
CVSSv2

CVE-2008-5363

Published: 08/12/2008 Updated: 02/11/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ActionScript 2 virtual machine in Adobe Flash Player 10.x prior to 10.0.12.36 and 9.x prior to 9.0.151.0, and Adobe AIR prior to 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe air

adobe flash player

Vendor Advisories

Synopsis Critical: flash-plugin security update Type/Severity Security Advisory: Critical Topic An updated Adobe Flash Player package that fixes several security issues isnow available for Red Hat Enterprise Linux 3 and 4 ExtrasThis update has been rated as having critical security impact by the RedHat Sec ...
Synopsis Critical: flash-plugin security update Type/Severity Security Advisory: Critical Topic An updated Adobe Flash Player package that fixes several security issues isnow available for Red Hat Enterprise Linux 5 SupplementaryThis update has been rated as having critical security impact by the RedHat Se ...