Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb14 07 | — | Upgrade to Adobe Flash Player version 12.0.0.70 for WindowsUpgrade to Adobe Flash Player version 12.0.0.70 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.341 for LinuxUpgrade to Adobe Flash Player version 11.7.700.269 for WindowsUpgrade to Adobe Flash Player version 11.7.700.269 for Mac OS X | Feb 25, 2014 | Feb 21, 2014 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Feb 21, 2014 |
| Suse | — | Upgrade flash-player-kde4Upgrade flash-player-gnomeUpgrade flash-player | Dec 18, 2015 | Feb 21, 2014 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Feb 21, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub