CVE-2014-0532 is a cross-site scripting (XSS) vulnerability in Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, and Linux platforms. This flaw allows remote attackers to inject arbitrary web script or HTML through unspecified vectors. With a CVSS score of 4.3, it is a medium-severity vulnerability, requiring medium attack complexity but potentially leading to information disclosure (integrity impact is partial). There is no indication of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it has received some community discussion and media coverage, it is not listed in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.83:*:*:*:*:*:*:* | ||
<= 13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:* | ||
<= 13.0.0.214CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.