CVE-2014-9163 is a critical stack-based buffer overflow vulnerability in Adobe Flash Player affecting Windows, OS X, and Linux versions prior to specific updates. This flaw allows attackers to execute arbitrary code through unspecified vectors. With a CVSS score of 7.8 (High), the vulnerability requires user interaction (UI:R) but can lead to high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) if exploited. This CVE is listed in CISA's KEV catalog, confirming active exploitation in the wild in December 2014, and has garnered significant community discussion and media coverage, despite no public exploit code being readily available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0, < 13.0.0.259CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 14.0, <= 14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.0.0.246CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.2.202.425CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.