Back

HIGH

flash-plugin: multiple code execution or security bypass flaws (APSB14-18)

Published Aug 12, 2014

Description

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0540, CVE-2014-0542, CVE-2014-0544, and CVE-2014-0545.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner adobe
Published Aug 12, 2014
Updated Aug 6, 2024
Reserved Dec 20, 2013

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Critical
Public date Aug 12, 2014
Bugzilla 1129417

ENISA EUVD

Assigner adobe
Published Aug 12, 2014
Updated Aug 6, 2024

GitHub

No data