CVE-2014-8068
published 2014-10-09CVE-2014-8068: Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive…
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.79%
75.8th percentile
Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by book-navigation information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | digital_editions | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://arstechnica.com/security/2014/10/adobes-e-book-reader-sends-your-reading-logs-back-to-adobe-in-plain-text/http://secunia.com/advisories/61551http://the-digital-reader.com/2014/10/06/adobe-spying-users-collecting-data-ebook-libraries/http://twitter.com/AdobeSecurity/statuses/519826275008282624https://exchange.xforce.ibmcloud.com/vulnerabilities/97696http://arstechnica.com/security/2014/10/adobes-e-book-reader-sends-your-reading-logs-back-to-adobe-in-plain-text/http://secunia.com/advisories/61551http://the-digital-reader.com/2014/10/06/adobe-spying-users-collecting-data-ebook-libraries/http://twitter.com/AdobeSecurity/statuses/519826275008282624https://exchange.xforce.ibmcloud.com/vulnerabilities/97696
2014-10-09
Published