Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb14 27 | — | Upgrade to Adobe Flash Player version 13.0.0.259 for Mac OS XUpgrade to Adobe Flash Player version 16.0.0.235 for WindowsUpgrade to Adobe Flash Player version 11.2.202.425 for LinuxUpgrade to Adobe Flash Player version 16.0.0.235 for Mac OS XUpgrade to Adobe Flash Player version 13.0.0.259 for Windows | Dec 9, 2014 | Dec 9, 2014 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Dec 10, 2014 |
| Suse | — | Upgrade flash-player-kde4Upgrade flash-playerUpgrade flash-player-gnome | Dec 18, 2015 | Dec 10, 2014 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Dec 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub