← All CVEs

CVE-2014-0559

high · 10

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0556.

10
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2014-09-10
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
adobeadobe_air<= 14.0.0.178
adobeadobe_air13.0.0.83
adobeadobe_air13.0.0.111
adobeadobe_air14.0.0.110
adobeadobe_air14.0.0.137
applemac_os_xall versions
microsoftwindowsall versions
adobeflash_player<= 13.0.0.241
adobeflash_player13.0.0.182
adobeflash_player13.0.0.201
adobeflash_player13.0.0.206
adobeflash_player13.0.0.214
adobeflash_player13.0.0.223
adobeflash_player13.0.0.231
adobeflash_player14.0.0.125
adobeflash_player14.0.0.145
adobeflash_player14.0.0.176
adobeflash_player14.0.0.179
adobeflash_player15.0.0.144
applemac_os_xall versions
microsoftwindowsall versions
adobeadobe_air_sdk<= 14.0.0.178
adobeadobe_air_sdk13.0.0.83
adobeadobe_air_sdk13.0.0.111
adobeadobe_air_sdk14.0.0.110
adobeadobe_air_sdk14.0.0.137
adobeadobe_air<= 14.0.0.179
adobeadobe_air13.0.0.83
adobeadobe_air13.0.0.111
adobeadobe_air14.0.0.110
adobeadobe_air14.0.0.137
googleandroidall versions
adobeflash_player<= 11.2.202.400
adobeflash_player11.2.202.223
adobeflash_player11.2.202.228
adobeflash_player11.2.202.233
adobeflash_player11.2.202.235
adobeflash_player11.2.202.236
adobeflash_player11.2.202.238
adobeflash_player11.2.202.243

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0559