CVE-2014-0540 is a critical vulnerability affecting Adobe Flash Player and AIR across Windows, OS X, and Linux platforms. It allows attackers to bypass Address Space Layout Randomization (ASLR) by discovering memory addresses, facilitating further exploitation. With a CVSS score of 10.0, this vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required. While there is no public exploit code available, it was reportedly leveraged in targeted attacks, and it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.0.137CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.83:*:*:*:*:*:*:* | ||
13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.111:*:*:*:*:*:*:* | ||
14.0.0.110CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:14.0.0.110:*:*:*:*:*:*:* | ||
<= 14.0.0.137CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.