Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb14 17 | — | Upgrade to Adobe Flash Player version 13.0.0.231 for Mac OS XUpgrade to Adobe Flash Player version 14.0.0.145 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.394 for LinuxUpgrade to Adobe Flash Player version 14.0.0.145 for WindowsUpgrade to Adobe Flash Player version 13.0.0.231 for Windows | Jul 8, 2014 | Jul 8, 2014 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jul 9, 2014 |
| Suse | — | Upgrade flash-playerUpgrade ruby2.5-rubygem-actionpack-5_1Upgrade flash-player-kde4Upgrade flash-player-gnome | Dec 18, 2015 | Jul 9, 2014 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Jul 9, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub