Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-5361

EPSS 3.07% · P87
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-5361

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Adobe Flash Player ActionScript中多个畸形PDF敏感信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Flash Player是一款非常流行的FLASH播放器。 Adobe Flash Player 10.x 前的 10.0.12.36 版和 9.x 前的 9.0.151.0版和Adobe AIR 1.5以前的版本中的ActionScript 2虚拟机,在执行(1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, 和未明的其它动作时,没有正确验证一个成员元素的大小,这允许远程攻击者通过一个特制的PDF文件从进程内存中读取
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-5361

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-5361

Please Login to view more intelligence information

Same Patch Batch · n/a · 2008-12-08 · 20 CVEs total

CVE-2008-5375CMus 不安全临时文件创建漏洞
CVE-2008-5365ActiveWebSoftwares ActiveVotes 'VoteHistory.asp' SQL注入漏洞
CVE-2008-5364Adobe getPlus ActiveX控件栈溢出漏洞
CVE-2008-5363Adobe Flash Player ActionScript 畸形PDF文件拒绝服务漏洞
CVE-2008-5362Adobe Flash Player ActionScript 畸形PDF敏感信息泄露漏洞
CVE-2008-5380GpsDrive 'geo-nearest' 不安全临时文件创建漏洞
CVE-2008-5379Debian netdisco-mibs-installer symlink攻击漏洞
CVE-2008-5378ARB symlink攻击漏洞
CVE-2008-5377CUPS 'pstopdf' symlink攻击漏洞
CVE-2008-5376crip editcomment symlink攻击漏洞
CVE-2008-5366Debian 'ppp' 不安全临时文件创建漏洞
CVE-2008-5374bash-doc 不安全临时文件创建漏洞
CVE-2008-5373jose_luis_tallon bacula_common 不安全临时文件创建漏洞
CVE-2008-5372lessdisks.net sdm 不安全临时文件创建漏洞
CVE-2008-5371Screenie 不安全临时文件创建漏洞
CVE-2008-5370PvPGN 不安全临时文件创建漏洞
CVE-2008-5369noip2 不安全临时文件创建漏洞
CVE-2008-5368Muttprint 不安全临时文件创建漏洞
CVE-2008-5367Debian ppp-udeb 不安全临时文件创建漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-5361

No comments yet


Leave a comment