CVE-2017-2977 describes a buffer over-read vulnerability in Adobe Digital Editions versions 4.5.3 and earlier. This high-severity vulnerability (CVSS 7.5) could lead to information disclosure if successfully exploited, with an attacker potentially triggering it remotely without user interaction. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability was addressed by Adobe and covered by media outlets.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.3CPE matchmatch criteria | cpe:2.3:a:adobe:digital_editions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.