CVE-2014-0538 is a critical use-after-free vulnerability in Adobe Flash Player, AIR, and AIR SDK across Windows, OS X, Linux, and Android platforms. This flaw allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity. With a CVSS score of 10.0, it poses a severe risk of complete compromise to confidentiality, integrity, and availability. While no public exploit code is readily available, it was reportedly leveraged in targeted attacks, indicating active exploitation at the time, and garnered significant media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.394CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
11.2.202.223CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.223:*:*:*:*:*:*:* | ||
11.2.202.228CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.228:*:*:*:*:*:*:* | ||
11.2.202.233CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.233:*:*:*:*:*:*:* | ||
11.2.202.235CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.235:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.