← All CVEs

CVE-2014-0497

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added 2024-09-17Remediation due 2024-10-08

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

9.8
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2014-02-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-191

Affected products

VendorProductAffected versions
adobeflash_player< 11.2.202.336
linuxlinux_kernelall versions
adobeflash_player< 11.7.700.261
adobeflash_player>= 11.8.800.94, < 12.0.0.44
applemac_os_xall versions
microsoftwindowsall versions
googlechrome< 32.0.1700.107
applemacosall versions
googlechrome_osall versions
linuxlinux_kernelall versions
microsoftwindowsall versions
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.5
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus6.5
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0
opensuseopensuse11.4
opensuseopensuse12.3
opensuseopensuse13.1
suselinux_enterprise_desktop11
suselinux_enterprise_desktop11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0497