V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-0497
CVE
Critical KEVConfirmedExploit available

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before …

CVSS
9.8
Critical
EPSS
1.00
p99
Published
2014-01-01
Updated
2024-09-17
Description

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

Tags · CWE
KEVPre-auth
CWE-190
CWE-191
CAPEC-92
Affected products
Enterprise_linux_desktopEnterprise_linux_eusEnterprise_linux_serverEnterprise_linux_server_ausEnterprise_linux_workstation
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2014-01-01
Published
2024-09-17
Added to KEV
2024-09-17
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.999 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2014-0497
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
33212
exploitdb · https://www.exploit-db.com/exploits/33212
Enterprise
Affected products
ProductVendorStatus
flash-pluginExploited
flash-pluginExploited
chrome*Exploited
enterprise_linux_desktop*Exploited
enterprise_linux_eus*Exploited
enterprise_linux_server*Exploited
enterprise_linux_server_aus*Exploited
enterprise_linux_workstation*Exploited
flash_player*Exploited
flash_player*Exploited
linux_enterprise_desktop*Exploited
opensuse*Exploited
Source databases
CVE
RED