CVE-2014-0509
published 2014-04-08CVE-2014-0509: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.81%
84.9th percentile
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
159 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 4.0.0.1390 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player up to 12.0.0.77 cross site scripting (APSB14-09 / Nessus ID 73432)
vuldb·2026-05-10·CVSS 4.3
CVE-2014-0509 [MEDIUM] Adobe Flash Player up to 12.0.0.77 cross site scripting (APSB14-09 / Nessus ID 73432)
A vulnerability, which was classified as critical, was found in Adobe Flash Player up to 12.0.0.77. The affected element is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2014-0509. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-w988-3j4h-5xj8: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11
ghsa_unreviewed·2022-05-17
CVE-2014-0509 [MEDIUM] CWE-79 GHSA-w988-3j4h-5xj8: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Red Hat
flash-plugin: cross-site scripting flaw (APSB14-09)
vendor_redhat·2014-04-08·CVSS 4.3
CVE-2014-0509 [MEDIUM] CWE-79 flash-plugin: cross-site scripting flaw (APSB14-09)
flash-plugin: cross-site scripting flaw (APSB14-09)
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://www.securityfocus.com/bid/66703http://www.securitytracker.com/id/1030035http://helpx.adobe.com/security/products/flash-player/apsb14-09.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0380.htmlhttp://security.gentoo.org/glsa/glsa-201405-04.xmlhttp://www.securityfocus.com/bid/66703http://www.securitytracker.com/id/1030035
2014-04-08
Published