CVE-2014-0558
published 2014-10-15CVE-2014-0558: Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.07%
91.4th percentile
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 15.0.0.252 | — |
| adobe | adobe_air | <= 15.0.0.249 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 15.0.0.249 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | air_desktop_runtime | <= 15.0.0.249 | — |
| adobe | air_sdk | <= 15.0.0.249 | — |
| adobe | air_sdk | <= 15.0.0.252 | — |
| adobe | flash_player | <= 13.0.0.244 | — |
| adobe | flash_player | <= 11.2.202.406 | — |
| adobe | flash_player | <= 15.0.0.152 | — |
| adobe | flash_player | <= 15.0.0.167 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v62p-hc6h-7mcr: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2014-0558 [CRITICAL] CWE-94 GHSA-v62p-hc6h-7mcr: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.
GHSA
GHSA-jmf8-xc29-2wm7: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2014-0564 [CRITICAL] GHSA-jmf8-xc29-2wm7: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
OSV
CVE-2014-0558: Adobe Flash Player before 13
osv·2014-10-15·CVSS 10.0
CVE-2014-0558 [CRITICAL] CVE-2014-0558: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.
OSV
CVE-2014-0564: Adobe Flash Player before 13
osv·2014-10-15·CVSS 10.0
CVE-2014-0564 [CRITICAL] CVE-2014-0564: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
VulnCheck
Adobe Flash Player Arbitrary Code Execution
vulncheck·2014·CVSS 10.0
CVE-2014-0564 [CRITICAL] Adobe Flash Player Arbitrary Code Execution
Adobe Flash Player Arbitrary Code Execution
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://cisa.gov/news-events/alerts/2015/04/29/top-30-targeted-high-risk-vulnerabilities; https://www.us-cert.gov/ncas/alerts/TA15-119A
Red Hat
flash-plugin: multiple code execution flaws (APSB14-22)
vendor_redhat·2014-10-14·CVSS 10.0
CVE-2014-0558 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-22)
flash-plugin: multiple code execution flaws (APSB14-22)
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-22)
vendor_redhat·2014-10-14·CVSS 10.0
CVE-2014-0564 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-22)
flash-plugin: multiple code execution flaws (APSB14-22)
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
bugzilla·2014-10-14·CVSS 10.0
CVE-2014-0564 [CRITICAL] CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
Adobe has released Flash Player 11.2.202.411 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0564, CVE-2014-0558).
* These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2014-0569).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-22.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:1648 https://rhn.redhat.com/errata/RHSA-2014-1648.html
Bugzilla
CVE-2014-0199 ovirt-engine-reports: setup script logs database password in cleartext
bugzilla·2014-05-05·CVSS 2.1
CVE-2014-0199 [LOW] CVE-2014-0199 ovirt-engine-reports: setup script logs database password in cleartext
CVE-2014-0199 ovirt-engine-reports: setup script logs database password in cleartext
It was found that the ovirt-engine-reports setup script would log the reports database password in plaintext to a world-readable file. An attacker with a local user account on the RHEV-M server could use this flaw to access, read and modify the reports database.
Discussion:
Acknowledgements:
This issue was discovered by Red Hat.
---
*** Bug 1086248 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in following products:
RHEV Manager version 3.3
Via RHSA-2014:0558 https://rhn.redhat.com/errata/RHSA-2014-0558.html
Bugzilla
CVE-2014-0201 ovirt-engine-reports: various configuration files are world-readable
bugzilla·2014-05-05·CVSS 2.1
CVE-2014-0201 [LOW] CVE-2014-0201 ovirt-engine-reports: various configuration files are world-readable
CVE-2014-0201 ovirt-engine-reports: various configuration files are world-readable
It was found that multiple ovirt-engine-reports configuration files are world-readable. An attacker with a local user account on the RHEV-M server could use this flaw to access a variety of potentially sensitive information.
Discussion:
Acknowledgements:
This issue was discovered by Red Hat.
---
This issue has been addressed in following products:
RHEV Manager version 3.3
Via RHSA-2014:0558 https://rhn.redhat.com/errata/RHSA-2014-0558.html
Bugzilla
CVE-2014-0200 ovirt-engine-reports: js-jboss7-ds.xml is world-readable
bugzilla·2014-05-05·CVSS 2.1
CVE-2014-0200 [LOW] CVE-2014-0200 ovirt-engine-reports: js-jboss7-ds.xml is world-readable
CVE-2014-0200 ovirt-engine-reports: js-jboss7-ds.xml is world-readable
It was found that the RHEV-M reports datasource configuration file (js-jboss7-ds.xml) is world-readable. An attacker with a local user account on the RHEV-M server could use this flaw to access, read and modify the reports database.
Discussion:
Acknowledgements:
This issue was discovered by Red Hat.
---
This issue has been addressed in following products:
RHEV Manager version 3.3
Via RHSA-2014:0558 https://rhn.redhat.com/errata/RHSA-2014-0558.html
http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00033.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1648.htmlhttp://secunia.com/advisories/61980http://www.securitytracker.com/id/1031019http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00033.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1648.htmlhttp://secunia.com/advisories/61980http://www.securitytracker.com/id/1031019
2014-10-15
Published