CVE-2014-0497 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-10-08.
Description
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.88% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-191 |
| On CISA KEV | yes — remediate by 2024-10-08 |
| Public exploit | yes |
| Published | 2014-02-05 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Adobe Flash Player Integer Underflow Vulnerablity |
|---|---|
| Added | 2024-09-17 |
| Due | 2024-10-08 |
| Vendor / product | Adobe / Flash Player |
| Ransomware use | none reported |
Affected (14)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | mac os x |
| apple | macos |
| chrome | |
| chrome os | |
| linux | linux kernel |
| microsoft | windows |
| opensuse | opensuse |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux workstation |
| suse | linux enterprise desktop |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash Player - Integer Underflow Remote Code Execution (Metasploit) | 2014-05-06 |
References
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0137.html
- http://secunia.com/advisories/56437
- http://secunia.com/advisories/56737
- http://secunia.com/advisories/56780
- http://secunia.com/advisories/56799
- http://secunia.com/advisories/56839
- http://www.exploit-db.com/exploits/33212
- http://www.osvdb.org/102849
- http://www.securityfocus.com/bid/65327
- http://www.securitytracker.com/id/1029715
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
→ the Explorer · watch your stack · NVD