CVE-2014-0506
published 2014-03-27CVE-2014-0506: Use-after-free vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.61%
93.9th percentile
Use-after-free vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to execute arbitrary code, and possibly bypass an Internet Explorer sandbox protection mechanism, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player 12.0.0.77 on Windows resource management (Nessus ID 73432 / ID 121866)
vuldb·2026-05-09·CVSS 10.0
CVE-2014-0506 [CRITICAL] Adobe Flash Player 12.0.0.77 on Windows resource management (Nessus ID 73432 / ID 121866)
A vulnerability was found in Adobe Flash Player 12.0.0.77 on Windows. It has been rated as critical. This vulnerability affects unknown code. The manipulation leads to improper resource management.
This vulnerability is traded as CVE-2014-0506. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
VulDB
Adobe Flash Player 12.0.0.77 resource management (Nessus ID 73432 / ID 121866)
vuldb·2026-05-09·CVSS 10.0
CVE-2014-0506 [CRITICAL] Adobe Flash Player 12.0.0.77 resource management (Nessus ID 73432 / ID 121866)
A vulnerability categorized as critical has been discovered in Adobe Flash Player 12.0.0.77. This issue affects some unknown processing. The manipulation results in improper resource management.
This vulnerability is known as CVE-2014-0506. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-g8c9-p2wf-f6gp: Use-after-free vulnerability in Adobe Flash Player before 11
ghsa_unreviewed·2022-05-17
CVE-2014-0506 [HIGH] GHSA-g8c9-p2wf-f6gp: Use-after-free vulnerability in Adobe Flash Player before 11
Use-after-free vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to execute arbitrary code, and possibly bypass an Internet Explorer sandbox protection mechanism, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
Red Hat
flash-plugin: two flaws leading to code execution (APSB14-09)
vendor_redhat·2014-04-08·CVSS 10.0
CVE-2014-0506 [CRITICAL] flash-plugin: two flaws leading to code execution (APSB14-09)
flash-plugin: two flaws leading to code execution (APSB14-09)
Use-after-free vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to execute arbitrary code, and possibly bypass an Internet Explorer sandbox protection mechanism, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0506 CVE-2014-0507 flash-plugin: two flaws leading to code execution (APSB14-09)
bugzilla·2014-04-09·CVSS 10.0
CVE-2014-0506 [CRITICAL] CVE-2014-0506 CVE-2014-0507 flash-plugin: two flaws leading to code execution (APSB14-09)
CVE-2014-0506 CVE-2014-0507 flash-plugin: two flaws leading to code execution (APSB14-09)
Adobe has released Flash Player 11.2.202.350 for Linux to correct the following flaws:
These updates resolve a use-after-free vulnerability that could result in arbitrary code execution (CVE-2014-0506).
These updates resolve a buffer overflow vulnerability that could result in arbitrary code execution (CVE-2014-0507).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-09.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0380 https://rhn.redhat.com/errata/RHSA-2014-0380.html
Bugzilla
CVE-2014-0152 ovirt-engine-webadmin: session fixation
bugzilla·2014-03-28·CVSS 6.8
CVE-2014-0152 [MEDIUM] CVE-2014-0152 ovirt-engine-webadmin: session fixation
CVE-2014-0152 ovirt-engine-webadmin: session fixation
It was found that the oVirt web admin interface did not generate a new session ID after authenticating a user. A remote attacker could use this flaw to perform session fixation attacks.
Discussion:
Upstream bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1077446
Upstream patch commit:
http://gerrit.ovirt.org/#/c/25959/
---
Created ovirt-engine tracking bugs for this issue:
Affects: fedora-all [bug 1081912]
---
This issue has been addressed in following products:
RHEV Manager version 3.4
Via RHSA-2014:0506 https://rhn.redhat.com/errata/RHSA-2014-0506.html
http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://twitter.com/thezdi/statuses/443886338077495296http://www.pwn2own.com/2014/03/pwn2own-results-for-wednesday-day-one/http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://twitter.com/thezdi/statuses/443886338077495296http://www.pwn2own.com/2014/03/pwn2own-results-for-wednesday-day-one/
2014-03-27
Published