CVE-2014-0497
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Added 2024-09-17Remediation due 2024-10-08
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
9.8
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2014-02-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-191
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | flash_player | < 11.2.202.336 |
| linux | linux_kernel | all versions |
| adobe | flash_player | < 11.7.700.261 |
| adobe | flash_player | >= 11.8.800.94, < 12.0.0.44 |
| apple | mac_os_x | all versions |
| microsoft | windows | all versions |
| chrome | < 32.0.1700.107 | |
| apple | macos | all versions |
| chrome_os | all versions | |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 6.5 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_aus | 6.5 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| suse | linux_enterprise_desktop | 11 |
| suse | linux_enterprise_desktop | 11 |
Check a specific version with /api/v1/cve/match.
References
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0137.html
- http://secunia.com/advisories/56437
- http://secunia.com/advisories/56737
- http://secunia.com/advisories/56780
- http://secunia.com/advisories/56799
- http://secunia.com/advisories/56839
- http://www.exploit-db.com/exploits/33212
- http://www.osvdb.org/102849
- http://www.securityfocus.com/bid/65327
- http://www.securitytracker.com/id/1029715
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0137.html
- http://secunia.com/advisories/56437
- http://secunia.com/advisories/56737
- http://secunia.com/advisories/56780
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-0497