CVE-2008-2641Improper Input Validation in Adobe Acrobat 3D

Severity
10.0CRITICALNVD
EPSS
42.0%
top 2.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25
Latest updateMay 1

Description

Unspecified vulnerability in Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to an "input validation issue in a JavaScript method."

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader32 versions+31
NVDadobe/acrobat_3d14 versions+13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g44h-jfwm-hrw7: Unspecified vulnerability in Adobe Reader and Acrobat 72022-05-01
VulnCheck
Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2 Input Validation in a JavaScript Method Vulnerability2008

📋Vendor Advisories

1
Red Hat
acroread: input validation issue in a JavaScript method2008-06-23

💬Community

1
Bugzilla
CVE-2008-2641 acroread: input validation issue in a JavaScript method2008-06-24
CVE-2008-2641 — Improper Input Validation in Adobe | cvebase