CVE-2014-0502
HIGH KEVAdobe Flash Player <11.7.700.269-12.0.0.70 - RCE
Title source: llmDescription
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
References (9)
Scores
CVSS v3
8.8
EPSS
0.8895
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2024-09-17
VulnCheck KEV
2014-02-21
InTheWild.io
2018-12-13
ENISA EUVD
EUVD-2014-0533
Classification
CWE
CWE-415
Status
draft
Affected Products (15)
adobe/flash_player
< 11.7.700.269
adobe/adobe_air_sdk
< 4.0.0.1628
adobe/adobe_air
< 4.0.0.1628
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
suse/linux_enterprise_desktop
redhat/enterprise_linux_desktop
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
redhat/enterprise_linux_server
redhat/enterprise_linux_server
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_workstation
redhat/enterprise_linux_workstation
Timeline
Published
Feb 21, 2014
KEV Added
Sep 17, 2024
Tracked Since
Feb 18, 2026