CVE-2014-0492

Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
adobeflash_player
11.0 ≤
𝑥
< 11.7.700.260
adobeflash_player
11.8 ≤
𝑥
< 11.8.800.175
adobeflash_player
11.9 ≤
𝑥
< 12.0.0.38
adobeadobe_air_sdk
𝑥
< 4.0.0.1390
adobeflash_player
11.0 ≤
𝑥
< 11.2.202.335
adobeadobe_air
𝑥
< 4.0.0.1390
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
saucy
Fixed 11.2.202.335-0saucy1
released
raring
Fixed 11.2.202.335-0raring1
released
quantal
Fixed 11.2.202.335-0quantal1
released
precise
Fixed 11.2.202.335-0precise1
released
lucid
ignored
flashplugin-nonfree
saucy
Fixed 11.2.202.335ubuntu0.13.10.1
released
raring
Fixed 11.2.202.335ubuntu0.13.04.1
released
quantal
Fixed 11.2.202.335ubuntu0.12.10.1
released
precise
Fixed 11.2.202.335ubuntu0.12.04.1
released
lucid
ignored
Common Weakness Enumeration