Lucene search

K
cve[email protected]CVE-2014-5333
HistoryAug 19, 2014 - 11:16 a.m.

CVE-2014-5333

2014-08-1911:16:59
CWE-352
web.nvd.nist.gov
40
cve-2014-5333
adobe flash player
adobe air
csrf attacks
swf file format
jsonp endpoints
information security
vulnerability
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a ‘$’ (dollar sign) or ‘(’ (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.

Affected configurations

NVD
Node
adobeadobe_airRange14.0.0.137
OR
adobeadobe_airMatch13.0.0.83
OR
adobeadobe_airMatch13.0.0.111
OR
adobeadobe_airMatch14.0.0.110
AND
googleandroid
Node
adobeflash_playerRange13.0.0.231
OR
adobeflash_playerMatch13.0.0.182
OR
adobeflash_playerMatch13.0.0.201
OR
adobeflash_playerMatch13.0.0.206
OR
adobeflash_playerMatch13.0.0.214
OR
adobeflash_playerMatch13.0.0.223
OR
adobeflash_playerMatch14.0.0.125
OR
adobeflash_playerMatch14.0.0.145
AND
applemac_os_x
OR
microsoftwindows
Node
adobeadobe_air_sdkRange14.0.0.137
OR
adobeadobe_air_sdkMatch13.0.0.83
OR
adobeadobe_air_sdkMatch13.0.0.111
OR
adobeadobe_air_sdkMatch14.0.0.110
Node
adobeflash_playerRange11.2.202.394
OR
adobeflash_playerMatch11.2.202.223
OR
adobeflash_playerMatch11.2.202.228
OR
adobeflash_playerMatch11.2.202.233
OR
adobeflash_playerMatch11.2.202.235
OR
adobeflash_playerMatch11.2.202.236
OR
adobeflash_playerMatch11.2.202.238
OR
adobeflash_playerMatch11.2.202.243
OR
adobeflash_playerMatch11.2.202.251
OR
adobeflash_playerMatch11.2.202.258
OR
adobeflash_playerMatch11.2.202.261
OR
adobeflash_playerMatch11.2.202.262
OR
adobeflash_playerMatch11.2.202.270
OR
adobeflash_playerMatch11.2.202.273
OR
adobeflash_playerMatch11.2.202.275
OR
adobeflash_playerMatch11.2.202.280
OR
adobeflash_playerMatch11.2.202.285
OR
adobeflash_playerMatch11.2.202.291
OR
adobeflash_playerMatch11.2.202.297
OR
adobeflash_playerMatch11.2.202.310
OR
adobeflash_playerMatch11.2.202.332
OR
adobeflash_playerMatch11.2.202.335
OR
adobeflash_playerMatch11.2.202.336
OR
adobeflash_playerMatch11.2.202.341
OR
adobeflash_playerMatch11.2.202.346
OR
adobeflash_playerMatch11.2.202.350
OR
adobeflash_playerMatch11.2.202.356
OR
adobeflash_playerMatch11.2.202.359
OR
adobeflash_playerMatch11.2.202.378
AND
linuxlinux_kernel
Node
adobeadobe_airRange14.0.0.110
OR
adobeadobe_airMatch13.0.0.83
OR
adobeadobe_airMatch13.0.0.111
AND
applemac_os_x
OR
microsoftwindows

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%