CVE-2014-0547 is a critical memory corruption vulnerability affecting multiple versions of Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, Linux, and Android platforms. With a CVSS score of 10.0, it allows unauthenticated attackers to execute arbitrary code or cause a denial of service over a network with low attack complexity. While no public exploit code is available and it's not listed in CISA's KEV catalog, the vulnerability garnered significant community discussion and media coverage at the time of its disclosure. Its FAUCET Risk Score of 86/100 indicates a high potential impact despite the lack of current active exploitation intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.241CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
13.0.0.182CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:* | ||
13.0.0.201CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:* | ||
13.0.0.206CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:* | ||
13.0.0.214CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.214:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.