CVE-2014-9162 is a critical information disclosure vulnerability affecting Adobe Flash Player versions prior to 13.0.0.259, 14.x through 16.x before 16.0.0.235 on Windows and OS X, and before 11.2.202.425 on Linux. With a CVSS score of 10.0, this vulnerability allows unauthenticated attackers to obtain sensitive information with low attack complexity, posing a severe risk of confidentiality, integrity, and availability compromise. Although it is not listed in CISA's KEV catalog, SecurityWeek reported that this vulnerability was actively exploited in the wild, indicating a real-world threat despite the lack of public exploit code or Metasploit modules. The vulnerability has garnered some community discussion and media coverage, reflecting its significance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0, < 13.0.0.259CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 14.0, <= 14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.0.0.235CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.2.202.425CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.