CVE-2014-0517Adobe AIR vulnerability

CWE-26410 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.0%
top 16.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateMay 14

Description

Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0518, CVE-2014-0519, and CVE-2014-0520.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDadobe/flash_player13.013.0.0.214+1
NVDadobe/adobe_air< 13.0.0.111

🔴Vulnerability Details

3
GHSA
GHSA-6qqf-wvh2-p8rg: Adobe Flash Player before 132022-05-14
OSV
CVE-2014-0517: Adobe Flash Player before 132014-05-14
CVEList
CVE-2014-0517: Adobe Flash Player before 132014-05-14

📋Vendor Advisories

4
Red Hat
flash-plugin: security protection bypass (APSB14-14)2014-05-13
Red Hat
flash-plugin: security protection bypass (APSB14-14)2014-05-13
Red Hat
flash-plugin: security protection bypass (APSB14-14)2014-05-13
Red Hat
flash-plugin: security protection bypass (APSB14-14)2014-05-13

💬Community

2
Bugzilla
CVE-2014-0517 CVE-2014-0518 CVE-2014-0519 CVE-2014-0520 flash-plugin: security protection bypass (APSB14-14)2014-05-13
Bugzilla
CVE-2013-6470 openstack foreman-installer: insecure defaults2014-01-13
CVE-2014-0517 — Adobe AIR vulnerability | cvebase