VDB

CVE-2014-8439

CVE-2014-8439 PUBLISHED KEV CVSS 8.800000190734863 HIGH

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.

EPSS 20.37% · 97.4th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
20.37%
97.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSflashplugin-nonfree11.2.202.310ubuntu1, 11.2.202.327ubuntu0.13.10.1, 11.2.202.332ubuntu1

Timeline

  • CVE Published
  • Oct 14, 2014 VulnCheck KEV Exploitation
  • Oct 14, 2014 PoC Published
  • Jan 27, 2015 VulnCheck KEV Exploitation
  • Feb 4, 2018 VulnCheck KEV Exploitation
  • Aug 17, 2021 VulnCheck KEV Exploitation
  • Feb 4, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • May 25, 2022 CISA KEV Added
  • May 25, 2022 VulnCheck KEV Exploitation
  • Jul 12, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›