CVE-2014-0497

9.8 CRITICAL CISA KEV - Actively Exploited
Published: February 05, 2014 Modified: October 22, 2025

Description

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
Source: psirt@adobe.com
Broken Link Patch Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2014-0137.html
Source: psirt@adobe.com
Third Party Advisory
http://secunia.com/advisories/56437
Source: psirt@adobe.com
Broken Link Third Party Advisory
http://secunia.com/advisories/56737
Source: psirt@adobe.com
Broken Link Third Party Advisory
http://secunia.com/advisories/56780
Source: psirt@adobe.com
Broken Link Third Party Advisory
http://secunia.com/advisories/56799
Source: psirt@adobe.com
Broken Link Third Party Advisory
http://secunia.com/advisories/56839
Source: psirt@adobe.com
Broken Link Third Party Advisory
http://www.exploit-db.com/exploits/33212
Source: psirt@adobe.com
Third Party Advisory VDB Entry
http://www.osvdb.org/102849
Source: psirt@adobe.com
Broken Link
http://www.securityfocus.com/bid/65327
Source: psirt@adobe.com
Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029715
Source: psirt@adobe.com
Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
Source: psirt@adobe.com
Third Party Advisory VDB Entry
http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.html
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
http://rhn.redhat.com/errata/RHSA-2014-0137.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/56437
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory
http://secunia.com/advisories/56737
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory
http://secunia.com/advisories/56780
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory
http://secunia.com/advisories/56799
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory
http://secunia.com/advisories/56839
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory
http://www.exploit-db.com/exploits/33212
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.osvdb.org/102849
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.securityfocus.com/bid/65327
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029715
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry

33 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
EPSS (Exploit Probability)
93.3%
100th percentile
Exploitation Status
Actively Exploited
Remediation due: 2024-10-08

Weaknesses (CWE)

Affected Vendors

suse redhat adobe linux google microsoft apple opensuse