CVE-2014-0497
Adobe Flash Player Integer Underflow Vulnerablity
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.88% probability · 100th percentile
- CISA KEV
- Listed 17 September 2024 · due 8 October 2024
- Weakness
- CWE-191
- Affected
- adobe/flash player · google/chrome · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · opensuse/opensuse · suse/linux enterprise desktop
- Source
- psirt@adobe.com
CISA notes
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2014-0497
References
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.htmlRelease Notes
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.htmlBroken Link, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.htmlMailing List
- http://rhn.redhat.com/errata/RHSA-2014-0137.htmlThird Party Advisory
- http://secunia.com/advisories/56437Broken Link, Third Party Advisory
- http://secunia.com/advisories/56737Broken Link, Third Party Advisory
- http://secunia.com/advisories/56780Broken Link, Third Party Advisory
- http://secunia.com/advisories/56799Broken Link, Third Party Advisory
- http://secunia.com/advisories/56839Broken Link, Third Party Advisory
- http://www.exploit-db.com/exploits/33212Third Party Advisory, VDB Entry
- http://www.osvdb.org/102849Broken Link
- http://www.securityfocus.com/bid/65327Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029715Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90884Third Party Advisory, VDB Entry
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.htmlRelease Notes
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.htmlBroken Link, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.htmlMailing List
- http://rhn.redhat.com/errata/RHSA-2014-0137.htmlThird Party Advisory
- http://secunia.com/advisories/56437Broken Link, Third Party Advisory
- http://secunia.com/advisories/56737Broken Link, Third Party Advisory
- http://secunia.com/advisories/56780Broken Link, Third Party Advisory
- http://secunia.com/advisories/56799Broken Link, Third Party Advisory
- http://secunia.com/advisories/56839Broken Link, Third Party Advisory
- http://www.exploit-db.com/exploits/33212Third Party Advisory, VDB Entry
- http://www.osvdb.org/102849Broken Link
- http://www.securityfocus.com/bid/65327Broken Link, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.