CVE-2014-0556 is a critical heap-based buffer overflow vulnerability in Adobe Flash Player, AIR, and their SDKs across Windows, OS X, and Linux platforms. With a CVSS score of 10.0, it allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability has known Metasploit exploit modules and was actively exploited in the wild shortly after its patch, as evidenced by significant media coverage and community discussion. Although not on the CISA KEV catalog, its high EPSS score and FAUCET Risk Score indicate a severe and exploitable threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.241CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
13.0.0.182CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:* | ||
13.0.0.201CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:* | ||
13.0.0.206CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:* | ||
13.0.0.214CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.214:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.