CVE-2008-0655

HIGH KEV

Adobe Acrobat and Reader < 8.1.2 - Exposure of Sensitive Information

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2008-0655 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 8, 2022.

Description

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

References (21)

Core 21
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1019346
Broken Link, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-043A.html
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1966/references
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28851
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28983
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200803-01.xml
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29065
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30840
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29205
Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27641
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0425
Broken Link, Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28802
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0144.html

Scores

CVSS v3 8.8
EPSS 0.6729
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-06-08
VulnCheck KEV 2008-02-09
InTheWild.io 2008-02-09
ENISA EUVD EUVD-2008-0665
CWE
CWE-200
Status published
Products (2)
adobe/acrobat < 8.1.2
adobe/acrobat_reader < 8.1.2
Published Feb 07, 2008
KEV Added Jun 08, 2022
Tracked Since Feb 18, 2026