CVE-2014-0498

Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified vectors.
Severity
UNKNOWN
AV:N/AC:L/Au:N/C:C/I:C/A:C
Atk. Vector
NETWORK
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
adobeflash_player
11.0 ≤
𝑥
< 11.7.700.269
adobeflash_player
11.8 ≤
𝑥
< 11.8.800.175
adobeflash_player
11.9 ≤
𝑥
< 12.0.0.70
adobeadobe_air_sdk
𝑥
< 4.0.0.1628
adobeflash_player
11.0 ≤
𝑥
< 11.2.202.341
adobeadobe_air
𝑥
< 4.0.0.1628
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
saucy
Fixed 11.2.202.341-0saucy1
released
quantal
Fixed 11.2.202.341-0quantal1
released
precise
Fixed 11.2.202.341-0precise1
released
lucid
ignored
flashplugin-nonfree
saucy
Fixed 11.2.202.341ubuntu0.13.10.1
released
quantal
Fixed 11.2.202.341ubuntu0.12.10.1
released
precise
Fixed 11.2.202.341ubuntu0.12.04.1
released
lucid
ignored