CVE-2014-0553
published 2014-09-10CVE-2014-0553: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.32%
94.8th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 14.0.0.179 | — |
| adobe | adobe_air | <= 14.0.0.178 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 14.0.0.178 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | flash_player | <= 13.0.0.241 | — |
| adobe | flash_player | <= 11.2.202.400 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6fxv-8xp9-724h: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14
CVE-2014-0553 [HIGH] GHSA-6fxv-8xp9-724h: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2014-0553: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2014-09-10·CVSS 10.0
CVE-2014-0553 [CRITICAL] CVE-2014-0553: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors.
Red Hat
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
vendor_redhat·2014-09-09·CVSS 10.0
CVE-2014-0553 [CRITICAL] flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
HackerOne
Adobe Flash Player MP4 Use-After-Free Vulnerability
hackerone·2015-03-11
Adobe Flash Player MP4 Use-After-Free Vulnerability
Adobe Flash Player MP4 Use-After-Free Vulnerability
I. Summary
Adobe Flash Player is prone to a vulnerability which leads to Use-After-Free. After parsing a malformed mp4 file, Flash will keep on accessing a block of memory for timing. Such memory block is still accessed even the page containing Flash is closed, which leads to a memory crash.
II. Description
Adobe Flash is a multimedia and software platform used for authoring of vector graphics, animation, games and rich Internet applications (RIAs) that can be viewed, played and executed in Adobe Flash Player. NetStream object can load and play an external mp4 file.
After playing a mp4 file, Flash will keep on updating a counter that saves the current frame and duration. A malformed mp4 file will trick the Flash to believe that this film
Bugzilla
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
bugzilla·2014-09-09·CVSS 10.0
CVE-2014-0547 [CRITICAL] CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Adobe has released Flash Player 11.2.202.406 for Linux to correct the following flaws:
* These updates resolve memory leakage vulnerabilities that could be used to bypass memory address randomization (CVE-2014-0557).
* These updates resolve a security bypass vulnerability (CVE-2014-0554).
* These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2014-0553).
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, CV
http://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.securityfocus.com/bid/69707http://www.securitytracker.com/id/1030822https://exchange.xforce.ibmcloud.com/vulnerabilities/95823http://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.securityfocus.com/bid/69707http://www.securitytracker.com/id/1030822https://exchange.xforce.ibmcloud.com/vulnerabilities/95823
2014-09-10
Published