CVE-2014-0557 is a memory address disclosure vulnerability affecting multiple versions of Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, Linux, and Android platforms. This flaw allows attackers to bypass Address Space Layout Randomization (ASLR), a crucial security mechanism, through unspecified vectors. With a CVSS score of 10.0, this vulnerability is critical, indicating a network-based attack with low complexity that could lead to complete compromise of confidentiality, integrity, and availability. While no public exploit code is available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog, the vulnerability did receive some media coverage and community discussion at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.400CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
11.2.202.223CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.223:*:*:*:*:*:*:* | ||
11.2.202.228CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.228:*:*:*:*:*:*:* | ||
11.2.202.233CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.233:*:*:*:*:*:*:* | ||
11.2.202.235CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.2.202.235:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.