VDB
CVE-2014-0498
CVE-2014-0498
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified vectors.
EPSS 1.16% · 79.0th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
1.16%
79.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| adobe | adobe_air | 0, 0 |
| adobe | flash_player | 11.0, 11.8, 11.0 |
| n/a | n/a | n/a |
| adobe | adobe_air_sdk | 0, 0 |
Exploit Intelligence
- openSUSE-SU-2014:0278 (circl)
- GLSA-201405-04 (circl)
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html (circl)
- RHSA-2014:0196 (circl)
- SUSE-SU-2014:0290 (circl)
- openSUSE-SU-2014:0277 (circl)
- (vulncheck-reported-exploitation)
- (vulncheck-reported-exploitation)
- (vulncheck-reported-exploitation)
- (vulncheck-reported-exploitation)
…and 4 more exploits
Timeline
- Jan 1, 2012 VulnCheck KEV Exploitation
- Nov 16, 2012 VulnCheck KEV Exploitation
- Mar 21, 2013 VulnCheck KEV Exploitation
- Feb 21, 2014 CVE Published
- Oct 22, 2014 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
References
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0498 advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html url
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html url
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html url
- http://rhn.redhat.com/errata/RHSA-2014-0196.html url
- http://security.gentoo.org/glsa/glsa-201405-04.xml url