CVE-2014-0503 describes a Same Origin Policy bypass vulnerability in Adobe Flash Player versions prior to 11.7.700.272 and 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux. This flaw, rated with a CVSS score of 6.4, allows remote attackers to potentially access sensitive information or manipulate content across different origins, impacting confidentiality and integrity. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability received some community discussion and media coverage at the time of its disclosure. It is not listed in CISA's KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, < 11.2.202.346CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.7.700.272CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.8, < 12.0.0.77CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.