CVE-2017-11297 is a memory corruption vulnerability affecting Adobe Digital Editions 4.5.6 and earlier versions, potentially leading to the disclosure of memory addresses. With a CVSS score of 5.3 (Medium), it can be exploited over the network with low attack complexity and no user interaction, though its impact is limited to confidentiality. There is no evidence of active exploitation, nor are there publicly available exploit modules in common frameworks like Metasploit or Nuclei, and it is not listed on the CISA KEV catalog. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.6CPE matchmatch criteria | cpe:2.3:a:adobe:digital_editions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.