CVE-2014-0508
published 2014-04-08CVE-2014-0508: Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.72%
90.9th percentile
Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Affected
159 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 4.0.0.1390 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player up to 12.0.0.77 access control (APSB14-09 / Nessus ID 73432)
vuldb·2026-05-10·CVSS 5.0
CVE-2014-0508 [MEDIUM] Adobe Flash Player up to 12.0.0.77 access control (APSB14-09 / Nessus ID 73432)
A vulnerability, which was classified as critical, has been found in Adobe Flash Player up to 12.0.0.77. Impacted is an unknown function. This manipulation causes improper access controls.
This vulnerability appears as CVE-2014-0508. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
GHSA-3hh5-r29m-w2h9: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-17
CVE-2014-0508 [MEDIUM] GHSA-3hh5-r29m-w2h9: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Red Hat
flash-plugin: information disclosure flaw (APSB14-09)
vendor_redhat·2014-04-08·CVSS 5.0
CVE-2014-0508 [MEDIUM] flash-plugin: information disclosure flaw (APSB14-09)
flash-plugin: information disclosure flaw (APSB14-09)
Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://www.securitytracker.com/id/1030035http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://www.securitytracker.com/id/1030035
2014-04-08
Published