MEDIUM · 4.3

CVE-2008-5363

The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dicti...

Vulnerability Description

The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
AdobeAir< 1.5
AdobeFlash Player>= 9.0.16.0, < 9.0.151.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-5363?

CVE-2008-5363 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dicti...

How severe is CVE-2008-5363?

CVE-2008-5363 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-5363?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Air, Adobe Flash Player.