CVE-2008-5361
Last modified
CVE-2008-5361 is a vulnerability of currently unknown severity. The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.. EPSS estimates a 3.80% chance of exploitation in the next 30 days.
Description
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Air | < 1.5 |
| Adobe | Flash Player | >= 9.0.16.0, < 9.0.151.0 |
| Adobe | Flash Player | >= 10, < 10.0.12.36 |
References
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatch, Vendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party Advisory, VDB Entry
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatch, Vendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5361?
How severe is CVE-2008-5361?
How do I fix CVE-2008-5361?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5355The "Java Update" feature for Java Runtime Environment (JRE)…
- CVE-2008-5356Heap-based buffer overflow in Java Runtime Environment (JRE)…
- CVE-2008-5357Integer overflow in Java Runtime Environment (JRE) for Sun J…
- CVE-2008-5358Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update …
- CVE-2008-5359Buffer overflow in Java Runtime Environment (JRE) for Sun JD…
- CVE-2008-5360Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update …
- CVE-2008-5362The DefineConstantPool action in the ActionScript 2 virtual …
- CVE-2008-5363The ActionScript 2 virtual machine in Adobe Flash Player 10.…
- CVE-2008-5364Stack-based buffer overflow in the getPlus ActiveX control i…
- CVE-2008-5365SQL injection vulnerability in VoteHistory.asp in ActiveWebS…
- CVE-2008-5366The postinst script in ppp 2.4.4rel on Debian GNU/Linux allo…
- CVE-2008-5367ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local …
Are you affected by CVE-2008-5361?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
