CVE-2017-2981 describes a buffer over-read vulnerability in Adobe Digital Editions versions 4.5.3 and earlier. This flaw, with a CVSS score of 7.5 (HIGH), could allow an unauthenticated attacker to achieve information disclosure with low attack complexity. While the vulnerability is not listed in CISA's KEV catalog and lacks public exploit code (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage. Its EPSS score suggests a low likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.3CPE matchmatch criteria | cpe:2.3:a:adobe:digital_editions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.