CVE-2017-2980 is a buffer over-read vulnerability affecting Adobe Digital Editions versions 4.5.3 and earlier. This flaw could allow an unauthenticated attacker to disclose sensitive information. With a CVSS score of 7.5 (High), it presents a significant risk due to its network-based attack vector and low attack complexity. While not currently listed on the KEV catalog or Hot List, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.3CPE matchmatch criteria | cpe:2.3:a:adobe:digital_editions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.