CVE-2008-5363: Null Pointer Dereference
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5363?
CVE-2008-5363 has been classified with moderate severity as it can lead to a denial of service.
How do I fix CVE-2008-5363?
To fix CVE-2008-5363, update Adobe Flash Player to version 10.0.12.36 or later, or version 9.0.151.0 or later.
What software is affected by CVE-2008-5363?
CVE-2008-5363 affects Adobe Flash Player 9.x up to 9.0.151.0, Flash Player 10.x up to 10.0.12.36, and Adobe AIR before version 1.5.
Can CVE-2008-5363 be exploited remotely?
Yes, CVE-2008-5363 can be exploited remotely, allowing attackers to cause a denial of service.
What is the main impact of CVE-2008-5363?
The main impact of CVE-2008-5363 is a denial of service due to a NULL pointer dereference.