Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Jan 14, 2014 | Jan 14, 2014 |
| Adobe Flash Apsb14 02 | — | Upgrade to Adobe Flash Player version 12.0.0.38 for WindowsUpgrade to Adobe Flash Player version 11.7.700.260 for WindowsUpgrade to Adobe Flash Player version 12.0.0.38 for Mac OS XUpgrade to Adobe Flash Player version 11.7.700.260 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.335 for Linux | Jan 14, 2014 | Jan 14, 2014 |
| Freebsd | — | Upgrade linux-f10-flashplugin | Dec 10, 2025 | Jan 24, 2014 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jan 15, 2014 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-playerUpgrade flash-player-kde4 | Dec 18, 2015 | Jan 15, 2014 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Jan 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub