Published: 21/02/2014 Updated: 13/12/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Double free vulnerability in Adobe Flash Player prior to 11.7.700.269 and 11.8.x up to and including 12.0.x prior to on Windows and Mac OS X and prior to on Linux, Adobe AIR prior to on Android, Adobe AIR SDK prior to, and Adobe AIR SDK & Compiler prior to allows remote malicious users to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.

Vulnerability Trend

Affected Products

Vendor Product Versions
AdobeAdobe Air-, 1.0, 1.0.1,, 1.0.4990, 1.1,, 1.5,, 1.5.1,, 1.5.2, 1.5.3,,, 2.0.2,, 2.0.3,, 2.0.4,,, 2.6,,, 2.7,,,,, 2.7.1,,,,,,,,,,,,,,,,,,,,,,,,,,,
AdobeAdobe Air Sdk3.0.0.4080,,,,,,,,,,,,,,,,,,,,,,
AdobeFlash Player11.0,,, 11.1,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, 11.3.300.257, 11.3.300.262, 11.3.300.265, 11.3.300.268, 11.3.300.270, 11.3.300.271, 11.3.300.273, 11.4.402.265, 11.4.402.278, 11.4.402.287, 11.5.502.110, 11.5.502.135, 11.5.502.136, 11.5.502.146, 11.5.502.149, 11.6.602.167, 11.6.602.168, 11.6.602.171, 11.6.602.180, 11.7.700.169, 11.7.700.202, 11.7.700.203, 11.7.700.224, 11.7.700.225, 11.7.700.232, 11.7.700.242, 11.7.700.252, 11.7.700.257, 11.7.700.260, 11.7.700.261, 11.8.800.94, 11.8.800.97, 11.8.800.168, 11.8.800.174, 11.9.900.117, 11.9.900.152, 11.9.900.170, 11.9.900.700,,,,

Vendor Advisories

Double free vulnerability in Adobe Flash Player before 117700269 and 118x through 120x before 120070 on Windows and Mac OS X and before 112202341 on Linux, Adobe AIR before 4001628 on Android, Adobe AIR SDK before 4001628, and Adobe AIR SDK & Compiler before 4001628 allows remote attackers to execute arbitrary code via uns ...

