peter bassill · operator
$ cve CVE-2014-0497 JSON

CVE-2014-0497 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-10-08.

Description

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.88% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-191
On CISA KEVyes — remediate by 2024-10-08
Public exploityes
Published2014-02-05
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Integer Underflow Vulnerablity
Added2024-09-17
Due2024-10-08
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (14)

VendorProduct
adobeflash player
applemac os x
applemacos
googlechrome
googlechrome os
linuxlinux kernel
microsoftwindows
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
suselinux enterprise desktop

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD