4.3
CVSSv2

CVE-2014-0531

Published: 11/06/2014 Updated: 22/12/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Adobe Flash Player prior to 13.0.0.223 and 14.x prior to 14.0.0.125 on Windows and OS X and prior to 11.2.202.378 on Linux, Adobe AIR prior to 14.0.0.110, Adobe AIR SDK prior to 14.0.0.110, and Adobe AIR SDK & Compiler prior to 14.0.0.110 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe adobe air

adobe adobe air 13.0.0.83

adobe flash_player 13.0.0.206

adobe flash_player

adobe flash_player 13.0.0.182

adobe flash_player 13.0.0.201

adobe adobe air sdk

adobe adobe air sdk 13.0.0.83

adobe flash_player 11.2.202.341

adobe flash_player 11.2.202.336

adobe flash_player 11.2.202.280

adobe flash_player 11.2.202.275

adobe flash_player 11.2.202.243

adobe flash_player 11.2.202.238

adobe flash_player 11.2.202.356

adobe flash_player 11.2.202.310

adobe flash_player 11.2.202.297

adobe flash_player 11.2.202.262

adobe flash_player 11.2.202.261

adobe flash_player 11.2.202.233

adobe flash_player 11.2.202.228

adobe flash_player 11.2.202.223

adobe flash_player 11.2.202.335

adobe flash_player 11.2.202.332

adobe flash_player 11.2.202.273

adobe flash_player 11.2.202.270

adobe flash_player 11.2.202.236

adobe flash_player 11.2.202.235

adobe flash_player 11.2.202.350

adobe flash_player 11.2.202.346

adobe flash_player 11.2.202.291

adobe flash_player 11.2.202.285

adobe flash_player 11.2.202.258

adobe flash_player 11.2.202.251

Vendor Advisories

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 1300223 and 14x before 1400125 on Windows and OS X and before 112202378 on Linux, Adobe AIR before 1400110, Adobe AIR SDK before 1400110, and Adobe AIR SDK & Compiler before 1400110 allows remote attackers to inject arbitrary web script or HTML via unspecif ...