SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0503

Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

MEDIUM 6.4EPSS 4.29%

Does this matter?

Lower severity and a low EPSS score (4.29%). Track it; it rarely justifies an emergency change on its own.

Description

Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
4.29% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
adobe/flash player
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.