CVE-2014-0515 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 94.6% (pctl 100)
Patch early
A public exploit exists.
Description
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 94.57% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-04-29 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | mac os x |
| linux | linux kernel |
| microsoft | windows |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash Player - Shader Buffer Overflow (Metasploit) | 2014-05-12 |
References
- http://helpx.adobe.com/security/products/flash-player/apsb14-13.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2014-0447.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://www.securityfocus.com/bid/67092
- http://www.securitytracker.com/id/1030155
- http://helpx.adobe.com/security/products/flash-player/apsb14-13.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2014-0447.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://www.securityfocus.com/bid/67092
- http://www.securitytracker.com/id/1030155
→ the Explorer · watch your stack · NVD