The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Jun 19, 2012 | Dec 8, 2008 |
| Adobe Flash Apsb08 22 | — | Upgrade to Adobe Flash Player version 10.0.12.36 for LinuxUpgrade to Adobe Flash Player version 10.0.12.36 for Mac OS XUpgrade to Adobe Flash Player version 10.0.12.36 for Windows | Nov 19, 2012 | Dec 8, 2008 |
| Apple Osx Flashplayerplugin | — | Upgrade macOS to the latest versionApply OS X security update 2008-008 | Dec 16, 2011 | Dec 8, 2008 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Dec 8, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub