Lucene search

K
cveAdobeCVE-2014-0492
HistoryJan 15, 2014 - 4:13 p.m.

CVE-2014-0492

2014-01-1516:13:04
CWE-264
adobe
web.nvd.nist.gov
54
adobe flash player
cve-2014-0492
aslr
security vulnerability
windows
mac os x
linux
adobe air
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.136

Percentile

95.6%

Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an “address leak.”

Affected configurations

Nvd
Node
adobeflash_playerRange11.011.7.700.260
OR
adobeflash_playerRange11.811.8.800.175
OR
adobeflash_playerRange11.912.0.0.38
AND
applemac_os_x
OR
microsoftwindowsMatch-
Node
adobeadobe_air_sdkRange<4.0.0.1390
Node
adobeflash_playerRange11.011.2.202.335
AND
linuxlinux_kernel
Node
adobeadobe_airRange<4.0.0.1390
VendorProductVersionCPE
adobeflash_player*cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
applemac_os_x*cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
adobeadobe_air_sdk*cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:*
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
adobeadobe_air*cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.136

Percentile

95.6%