CVE-2008-2992
גבוהה 7.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Reader and Acrobat Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 98% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-787
מוצרים מושפעים
adobe: acrobat; adobe: acrobat reader; oracle: solaris
קישורים
- http://secunia.com/advisories/29773 Broken LinkVendor Advisory
- http://secunia.com/advisories/32700 Broken LinkVendor Advisory
- http://secunia.com/advisories/32872 Broken LinkVendor Advisory
- http://secunia.com/advisories/35163 Broken LinkVendor Advisory
- http://secunia.com/secunia_research/2008-14/ Broken LinkVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-19.html Broken LinkPatchVendor Advisory
- http://www.vupen.com/english/advisories/2008/3001 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2009/0098 Broken LinkVendor Advisory
- http://secunia.com/advisories/29773 Broken LinkVendor Advisory
- http://secunia.com/advisories/32700 Broken LinkVendor Advisory