VDB

CVE-2014-9163

CVE-2014-9163 PUBLISHED KEV CVSS 7.800000190734863 HIGH

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

EPSS 20.72% · 97.4th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
20.72%
97.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSflashplugin-nonfree0, 11.2.202.310ubuntu1, 11.2.202.327ubuntu0.13.10.1

Timeline

  • Nov 14, 2014 CVE Published
  • Dec 9, 2014 VulnCheck KEV Exploitation
  • Dec 9, 2014 PoC Published
  • Dec 10, 2014 VulnCheck KEV Exploitation
  • Feb 10, 2015 VulnCheck KEV Exploitation
  • Dec 26, 2019 VulnCheck KEV Exploitation
  • Feb 4, 2022 EPSS Score
  • Apr 13, 2022 CISA KEV Added
  • Apr 13, 2022 VulnCheck KEV Exploitation
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›