CVE-2008-5362
published 2008-12-08CVE-2008-5362: The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.80%
88.9th percentile
The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count," which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 1.5 | 1.5 |
| adobe | flash_player | >= 10 < 10.0.12.36 | 10.0.12.36 |
| adobe | flash_player | >= 9.0.16.0 < 9.0.151.0 | 9.0.151.0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7p67-pjvg-2587: The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10
ghsa_unreviewed·2022-05-14
CVE-2008-5362 [MEDIUM] CWE-20 GHSA-7p67-pjvg-2587: The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10
The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count," which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
Red Hat
security flaw
vendor_redhat·2008-11-17·CVSS 4.3
CVE-2008-5362 [MEDIUM] security flaw
security flaw
The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count," which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/33390http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://securityreason.com/securityalert/4692http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://www.adobe.com/support/security/bulletins/apsb08-22.htmlhttp://www.isecpartners.com/advisories/2008-01-flash.txthttp://www.securityfocus.com/archive/1/498561/100/0/threadedhttp://secunia.com/advisories/33390http://secunia.com/advisories/34226http://security.gentoo.org/glsa/glsa-200903-23.xmlhttp://securityreason.com/securityalert/4692http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://www.adobe.com/support/security/bulletins/apsb08-22.htmlhttp://www.isecpartners.com/advisories/2008-01-flash.txthttp://www.securityfocus.com/archive/1/498561/100/0/threaded
2008-12-08
Published