CVE-2014-0509 describes a Cross-site Scripting (XSS) vulnerability in multiple versions of Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, Linux, and Android platforms. This flaw allows remote attackers to inject arbitrary web script or HTML through unspecified vectors. With a CVSS score of 4.3, it is a medium-severity vulnerability requiring medium attack complexity and impacting integrity, but it is not currently listed in CISA's KEV catalog. There is no public exploit intelligence available, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.0:*:*:*:*:*:*:* | ||
11.0.1.152CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.0.1.152:*:*:*:*:*:*:* | ||
11.0.1.153CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.0.1.153:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.1:*:*:*:*:*:*:* | ||
11.1.102.55CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.1.102.55:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.