CVE-2014-0569
HIGH severity · CVSS 9.3 · Integer overflow
9.3CVSS HIGH
Summary
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)90%
AV:N/AC:M/Au:N/C:C/I:C/A:C
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: http://helpx.adobe.com/security/products/flash-player/apsb14-22.html ↗
Additional information
- NVD record
- http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlPatch
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00002.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlAdvisory
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00033.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2014-1648.html
- http://secunia.com/advisories/61980Advisory
- http://www.securityfocus.com/bid/70441Advisory
- http://www.securitytracker.com/id/1031019Advisory