Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Sep 9, 2014 | Sep 9, 2014 |
| Adobe Flash Apsb14 21 | — | Upgrade to Adobe Flash Player version 13.0.0.244 for WindowsUpgrade to Adobe Flash Player version 15.0.0.152 for WindowsUpgrade to Adobe Flash Player version 13.0.0.244 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.406 for LinuxUpgrade to Adobe Flash Player version 15.0.0.152 for Mac OS X | Sep 9, 2014 | Sep 9, 2014 |
| Freebsd | — | Upgrade linux-f10-flashpluginUpgrade linux-c6-flashplugin | Dec 10, 2025 | Sep 25, 2014 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Sep 9, 2014 |
| Suse | — | Upgrade flash-player-kde4Upgrade flash-playerUpgrade flash-player-gnome | Dec 18, 2015 | Sep 9, 2014 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Sep 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub