CVE-2016-7888

Published on: 12/15/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:07 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Certain versions of Digital Editions from Adobe contain the following vulnerability:

Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak.

  • CVE-2016-7888 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.3 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED LOW NONE NONE

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL NONE NONE

CVE References

Description Tags Link
Adobe Digital Editions Address Leak and XML Parsing Error Let Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1037466
Adobe Digital Editions CVE-2016-7888 Information Disclosure Vulnerability cve.report (archive)
text/html
URL Logo BID 94880
ZDI-16-636 | Zero Day Initiative www.zerodayinitiative.com
text/html
URL Logo MISC www.zerodayinitiative.com/advisories/ZDI-16-636
Adobe Security Bulletin Patch
Vendor Advisory
helpx.adobe.com
text/html
URL Logo CONFIRM helpx.adobe.com/security/products/Digital-Editions/apsb16-45.html

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationAdobeDigital EditionsAllAllAllAll
  • cpe:2.3:a:adobe:digital_editions:*:*:*:*:*:*:*:*: