CVE-2014-0551 is a critical memory corruption vulnerability affecting Adobe Flash Player, Adobe AIR, and associated SDKs across Windows, OS X, and Linux platforms. With a CVSS score of 10.0, it allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service. While no public exploit code is available and it's not listed in CISA's KEV catalog, the vulnerability garnered significant media attention and community discussion at the time, indicating its perceived importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.0.178CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:* | ||
13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:13.0.0.111:*:*:*:*:*:*:* | ||
14.0.0.110CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:14.0.0.110:*:*:*:*:*:*:* | ||
14.0.0.137CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:14.0.0.137:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.