Vulnerability Details CVE-2008-5362
The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count," which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2008-5362
-
-
-
-
cpe:2.3:a:adobe:flash_player:10
-
cpe:2.3:a:adobe:flash_player:10.0.0.584
-
cpe:2.3:a:adobe:flash_player:10.0.12.10
-
cpe:2.3:a:adobe:flash_player:10.0.2.54
-
cpe:2.3:a:adobe:flash_player:9.0.112.0
-
cpe:2.3:a:adobe:flash_player:9.0.114.0
-
cpe:2.3:a:adobe:flash_player:9.0.115.0
-
cpe:2.3:a:adobe:flash_player:9.0.124.0
-
cpe:2.3:a:adobe:flash_player:9.0.125.0
-
cpe:2.3:a:adobe:flash_player:9.0.16.0
-
cpe:2.3:a:adobe:flash_player:9.0.18d60
-
cpe:2.3:a:adobe:flash_player:9.0.20
-
cpe:2.3:a:adobe:flash_player:9.0.20.0
-
cpe:2.3:a:adobe:flash_player:9.0.28
-
cpe:2.3:a:adobe:flash_player:9.0.28.0
-
cpe:2.3:a:adobe:flash_player:9.0.31
-
cpe:2.3:a:adobe:flash_player:9.0.31.0
-
cpe:2.3:a:adobe:flash_player:9.0.45.0
-
cpe:2.3:a:adobe:flash_player:9.0.47.0
-
cpe:2.3:a:adobe:flash_player:9.0.48.0