{"api_version":"1","generated_at":"2026-07-23T09:01:13+00:00","cve":"CVE-2008-5363","urls":{"html":"https://cve.report/CVE-2008-5363","api":"https://cve.report/api/cve/CVE-2008-5363.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5363","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5363"},"summary":{"title":"CVE-2008-5363","description":"The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-12-08 11:30:06","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-399","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.adobe.com/support/security/bulletins/apsb08-22.html","name":"http://www.adobe.com/support/security/bulletins/apsb08-22.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe - Security Advisories : APSB08-22 - Additional disclosure of security vulnerabilities fixed in Flash Player 10.0.12.36 and Flash Player 9.0.151.0","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200903-23.xml","name":"http://security.gentoo.org/glsa/glsa-200903-23.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  Adobe Flash Player: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4692","name":"http://securityreason.com/securityalert/4692","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33390","name":"http://secunia.com/advisories/33390","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/498561/100/0/threaded","name":"http://www.securityfocus.com/archive/1/498561/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.isecpartners.com/advisories/2008-01-flash.txt","name":"http://www.isecpartners.com/advisories/2008-01-flash.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"ASA-2009-020 (SUN 248586)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34226","name":"http://secunia.com/advisories/34226","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo update for netscape-flash - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5363","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5363","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5363","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"air","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5363","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:49:12.347Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20081122 Adobe Flash Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/498561/100/0/threaded"},{"name":"33390","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33390"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.isecpartners.com/advisories/2008-01-flash.txt"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb08-22.html"},{"name":"34226","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34226"},{"name":"4692","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4692"},{"name":"GLSA-200903-23","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200903-23.xml"},{"name":"248586","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-11-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20081122 Adobe Flash Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/498561/100/0/threaded"},{"name":"33390","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33390"},{"tags":["x_refsource_MISC"],"url":"http://www.isecpartners.com/advisories/2008-01-flash.txt"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm"},{"tags":["x_refsource_MISC"],"url":"http://www.adobe.com/support/security/bulletins/apsb08-22.html"},{"name":"34226","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34226"},{"name":"4692","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4692"},{"name":"GLSA-200903-23","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200903-23.xml"},{"name":"248586","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5363","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20081122 Adobe Flash Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/498561/100/0/threaded"},{"name":"33390","refsource":"SECUNIA","url":"http://secunia.com/advisories/33390"},{"name":"http://www.isecpartners.com/advisories/2008-01-flash.txt","refsource":"MISC","url":"http://www.isecpartners.com/advisories/2008-01-flash.txt"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm"},{"name":"http://www.adobe.com/support/security/bulletins/apsb08-22.html","refsource":"MISC","url":"http://www.adobe.com/support/security/bulletins/apsb08-22.html"},{"name":"34226","refsource":"SECUNIA","url":"http://secunia.com/advisories/34226"},{"name":"4692","refsource":"SREASON","url":"http://securityreason.com/securityalert/4692"},{"name":"GLSA-200903-23","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200903-23.xml"},{"name":"248586","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5363","datePublished":"2008-12-08T11:00:00.000Z","dateReserved":"2008-12-07T00:00:00.000Z","dateUpdated":"2024-08-07T10:49:12.347Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-12-08 11:30:06","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-399","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*","versionEndExcluding":"1.5","matchCriteriaId":"31300012-1803-451C-9304-7D532CAAD597"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.16.0","versionEndExcluding":"9.0.151.0","matchCriteriaId":"C9617651-EBE0-443C-9C56-75A6DB6DFA2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"10","versionEndExcluding":"10.0.12.36","matchCriteriaId":"24B27C65-29D0-42D7-8293-67839687888A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5363","Ordinal":"1","Title":"CVE-2008-5363","CVE":"CVE-2008-5363","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5363","Ordinal":"1","NoteData":"The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.","Type":"Description","Title":"CVE-2008-5363"},{"CveYear":"2008","CveId":"5363","Ordinal":"2","NoteData":"2008-12-08","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5363","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}