CVE-2014-0534 is an access restriction bypass vulnerability affecting Adobe Flash Player, AIR, AIR SDK, and AIR SDK & Compiler across Windows, OS X, and Linux platforms. With a CVSS score of 7.5, it is considered highly severe, allowing an unauthenticated attacker to achieve partial confidentiality, integrity, and availability impacts over a network with low attack complexity. While the vulnerability has garnered some media attention and community discussion, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.0.0.214CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
13.0.0.182CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:* | ||
13.0.0.201CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:* | ||
13.0.0.206CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:* | ||
<= 13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.