CVE-2014-0497 describes an integer underflow vulnerability in Adobe Flash Player across Windows, Mac OS X, and Linux platforms, allowing remote attackers to execute arbitrary code. This critical vulnerability, with a CVSS score of 9.8, requires no user interaction and can lead to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with public exploit code available, including a Metasploit module. The vulnerability has garnered significant community discussion and media coverage, highlighting its severe impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.2.202.336CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 11.7.700.261CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.8.800.94, < 12.0.0.44CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 32.0.1700.107CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.