Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-0556

86
FAUCET Score

CVE-2014-0556 is a critical heap-based buffer overflow vulnerability in Adobe Flash Player, AIR, and their SDKs across Windows, OS X, and Linux platforms. With a CVSS score of 10.0, it allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability has known Metasploit exploit modules and was actively exploited in the wild shortly after its patch, as evidenced by significant media coverage and community discussion. Although not on the CISA KEV catalog, its high EPSS score and FAUCET Risk Score indicate a severe and exploitable threat.

Impacted Technologies

VendorProductVersion(s)CPE
<= 13.0.0.241CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
13.0.0.182CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:*
13.0.0.201CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:*
13.0.0.206CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:*
13.0.0.214CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:13.0.0.214:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
84.30%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Metasploit: Adobe Flash Player copyPixelsToByteArray Method Integer Overflow · Sep 23, 2014
ExploitDB: EDB-36808 · Apr 21, 2015
This CVE's current EPSS score of 0.8430 is in the 100th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

adobepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: flash-plugin-0:11.2.202.406-1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: flash-plugin-0:11.2.202.406-1.el6
View patch

Vendor Advisories (1)

redhatCVE-2014-0556Critical

flash-plugin: multiple code execution or security bypass flaws (APSB14-21)

Sep 9, 2014

References

googleprojectzero.blogspot.com / 2014/09/exploiting-cve-2014-0556-in-flash.html
helpx.adobe.com / security/products/flash-player/apsb14-21.html
PatchVendor Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00006.html
lists.opensuse.org / opensuse-security-announce/2014-09/msg00016.html
lists.opensuse.org / opensuse-security-announce/2014-09/msg00021.html
packetstormsecurity.com / files/131516/Adobe-Flash-Player-copyPixelsToByteArray-Integer-Overflow.html
code.google.com / p/google-security-research/issues/detail
secunia.com / advisories/61089
security.gentoo.org / glsa/glsa-201409-05.xml
exchange.xforce.ibmcloud.com / vulnerabilities/95826
exploit-db.com / exploits/36808
osvdb.org / 111110
securityfocus.com / bid/69696
securitytracker.com / id/1030822