[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-8068Date: (C)2014-10-09   (M)2023-12-22


Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by book-navigation information.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-61551
adobe-digital-cve20148068-info-disc(97696)
http://arstechnica.com/security/2014/10/adobes-e-book-reader-sends-your-reading-logs-back-to-adobe-in-plain-text/
http://the-digital-reader.com/2014/10/06/adobe-spying-users-collecting-data-ebook-libraries/
http://twitter.com/AdobeSecurity/statuses/519826275008282624

CWE    1
CWE-200
OVAL    4
oval:org.secpod.oval:def:21851
oval:org.secpod.oval:def:21852
oval:org.secpod.oval:def:21850
oval:org.secpod.oval:def:21849
...

© SecPod Technologies