CVE-2008-5361
published 2008-12-08CVE-2008-5361: The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.80%
88.7th percentile
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 1.5 | 1.5 |
| adobe | flash_player | >= 10 < 10.0.12.36 | 10.0.12.36 |
| adobe | flash_player | >= 9.0.16.0 < 9.0.151.0 | 9.0.151.0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7p7w-xh5j-rhf6: The ActionScript 2 virtual machine in Adobe Flash Player 10
ghsa_unreviewed·2022-05-14
CVE-2008-5361 [MEDIUM] GHSA-7p7w-xh5j-rhf6: The ActionScript 2 virtual machine in Adobe Flash Player 10
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
Red Hat
security flaw
vendor_redhat·2008-11-17·CVSS 4.3
CVE-2008-5361 [MEDIUM] security flaw
security flaw
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/33390http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://securityreason.com/securityalert/4692http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://www.adobe.com/support/security/bulletins/apsb08-22.htmlhttp://www.isecpartners.com/advisories/2008-01-flash.txthttp://www.securityfocus.com/archive/1/498561/100/0/threadedhttp://secunia.com/advisories/33390http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://securityreason.com/securityalert/4692http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://www.adobe.com/support/security/bulletins/apsb08-22.htmlhttp://www.isecpartners.com/advisories/2008-01-flash.txthttp://www.securityfocus.com/archive/1/498561/100/0/threaded
2008-12-08
Published