CVE-2014-0532
published 2014-06-11CVE-2014-0532: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.79%
88.8th percentile
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0531 and CVE-2014-0533.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 13.0.0.111 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 13.0.0.111 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | flash_player | <= 13.0.0.214 | — |
| adobe | flash_player | <= 11.2.202.359 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple cross-site scripting flaws (APSB14-16)
vendor_redhat·2014-06-10·CVSS 4.3
CVE-2014-0533 [MEDIUM] CWE-79 flash-plugin: multiple cross-site scripting flaws (APSB14-16)
flash-plugin: multiple cross-site scripting flaws (APSB14-16)
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0531 and CVE-2014-0532.
Red Hat
flash-plugin: multiple cross-site scripting flaws (APSB14-16)
vendor_redhat·2014-06-10·CVSS 4.3
CVE-2014-0531 [MEDIUM] CWE-79 flash-plugin: multiple cross-site scripting flaws (APSB14-16)
flash-plugin: multiple cross-site scripting flaws (APSB14-16)
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.
Red Hat
flash-plugin: multiple cross-site scripting flaws (APSB14-16)
vendor_redhat·2014-06-10·CVSS 4.3
CVE-2014-0532 [MEDIUM] CWE-79 flash-plugin: multiple cross-site scripting flaws (APSB14-16)
flash-plugin: multiple cross-site scripting flaws (APSB14-16)
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0531 and CVE-2014-0533.
GHSA
GHSA-hf4g-m8gp-4vc2: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2014-0531 [MEDIUM] CWE-79 GHSA-hf4g-m8gp-4vc2: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.
GHSA
GHSA-jpm6-rmcp-5834: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2014-0532 [MEDIUM] CWE-79 GHSA-jpm6-rmcp-5834: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0531 and CVE-2014-0533.
GHSA
GHSA-467c-77hq-3qwx: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2014-0533 [MEDIUM] CWE-79 GHSA-467c-77hq-3qwx: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0531 and CVE-2014-0532.
OSV
CVE-2014-0531: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
osv·2014-06-11·CVSS 4.3
CVE-2014-0531 [MEDIUM] CVE-2014-0531: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.
OSV
CVE-2014-0532: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
osv·2014-06-11·CVSS 4.3
CVE-2014-0532 [MEDIUM] CVE-2014-0532: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0531 and CVE-2014-0533.
OSV
CVE-2014-0533: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
osv·2014-06-11·CVSS 4.3
CVE-2014-0533 [MEDIUM] CVE-2014-0533: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0531 and CVE-2014-0532.
No detection rules found.
No public exploits indexed.
http://helpx.adobe.com/security/products/flash-player/apsb14-16.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00030.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0745.htmlhttp://secunia.com/advisories/58390http://secunia.com/advisories/58465http://secunia.com/advisories/58585http://secunia.com/advisories/59053http://secunia.com/advisories/59304http://security.gentoo.org/glsa/glsa-201406-17.xmlhttp://www.securityfocus.com/bid/67973http://www.securitytracker.com/id/1030368http://helpx.adobe.com/security/products/flash-player/apsb14-16.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00030.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0745.htmlhttp://secunia.com/advisories/58390http://secunia.com/advisories/58465http://secunia.com/advisories/58585http://secunia.com/advisories/59053http://secunia.com/advisories/59304http://security.gentoo.org/glsa/glsa-201406-17.xmlhttp://www.securityfocus.com/bid/67973http://www.securitytracker.com/id/1030368
2014-06-11
Published