CVE-2014-0507
published 2014-04-08CVE-2014-0507: Buffer overflow in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.44%
93.0th percentile
Buffer overflow in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows attackers to execute arbitrary code via unspecified vectors.
Affected
159 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 4.0.0.1390 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player up to 12.0.0.77 memory corruption (APSB14-09 / Nessus ID 73432)
vuldb·2026-05-10·CVSS 9.3
CVE-2014-0507 [CRITICAL] Adobe Flash Player up to 12.0.0.77 memory corruption (APSB14-09 / Nessus ID 73432)
A vulnerability has been found in Adobe Flash Player up to 12.0.0.77 and classified as critical. The impacted element is an unknown function. Performing a manipulation results in memory corruption.
This vulnerability is known as CVE-2014-0507. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
GHSA-3c5p-wmcv-3jvc: Buffer overflow in Adobe Flash Player before 11
ghsa_unreviewed·2022-05-17
CVE-2014-0507 [HIGH] CWE-119 GHSA-3c5p-wmcv-3jvc: Buffer overflow in Adobe Flash Player before 11
Buffer overflow in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows attackers to execute arbitrary code via unspecified vectors.
Red Hat
flash-plugin: two flaws leading to code execution (APSB14-09)
vendor_redhat·2014-04-08·CVSS 9.3
CVE-2014-0507 [CRITICAL] flash-plugin: two flaws leading to code execution (APSB14-09)
flash-plugin: two flaws leading to code execution (APSB14-09)
Buffer overflow in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://www.securityfocus.com/bid/66701http://www.securitytracker.com/id/1030035http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://www.securityfocus.com/bid/66701http://www.securitytracker.com/id/1030035
2014-04-08
Published