CVE-2008-0655 describes multiple unspecified vulnerabilities in Adobe Reader and Acrobat versions prior to 8.1.2. This critical vulnerability (CVSS 9.8) has an unknown attack vector and impact, but it poses a severe risk of compromise to confidentiality, integrity, and availability. It is actively exploited in the wild, as indicated by its presence in the KEV catalog and a high EPSS score, despite a lack of public exploit code or Metasploit modules. The vulnerability has garnered significant community discussion and media coverage, highlighting its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.1.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
< 8.1.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.