CVE-2014-0577 is a critical type confusion vulnerability affecting Adobe Flash Player on Windows, OS X, and Linux, as well as Adobe AIR and its SDKs. This flaw allows attackers to execute arbitrary code remotely with low attack complexity. With a CVSS score of 10.0, it poses a severe risk of complete compromise (confidentiality, integrity, and availability). While not listed on CISA's KEV catalog, the vulnerability garnered significant community discussion and media coverage at the time, indicating its importance, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0, < 13.0.0.252CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 14.0, <= 14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.0.0.223CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.2.202.418CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.