7.8
CVSSv2

CVE-2014-0499

Published: 21/02/2014 Updated: 13/12/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Adobe Flash Player prior to 11.7.700.269 and 11.8.x up to and including 12.0.x prior to 12.0.0.70 on Windows and Mac OS X and prior to 11.2.202.341 on Linux, Adobe AIR prior to 4.0.0.1628 on Android, Adobe AIR SDK prior to 4.0.0.1628, and Adobe AIR SDK & Compiler prior to 4.0.0.1628 do not prevent access to address information, which makes it easier for malicious users to bypass the ASLR protection mechanism via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe adobe air sdk

adobe adobe air

Vendor Advisories

Adobe Flash Player before 117700269 and 118x through 120x before 120070 on Windows and Mac OS X and before 112202341 on Linux, Adobe AIR before 4001628 on Android, Adobe AIR SDK before 4001628, and Adobe AIR SDK & Compiler before 4001628 do not prevent access to address information, which makes it easier for attackers to b ...

Recent Articles

New Flash vuln exploited (again). Adobe posts emergency fix (again)
The Register • Shaun Nichols in San Francisco • 20 Feb 2014

Miscreants attack fresh hole ... Windows, Mac, Linux peeps at risk

Adobe has released an update to address critical flaws in its Flash Player software, one of which is being actively targeted in the wild. The company said that the Windows and Mac OS X builds of Flash Player 12.0.0.44 and earlier, and Flash Player 11.2.202.336 and earlier for Linux, must be upgraded to fix a trio of bugs. Adobe said today's update will "resolve a stack overflow vulnerability that could result in arbitrary code execution (CVE-2014-0498)", fix "a memory leak vulnerability that cou...