CVE-2014-0574
published 2014-11-11CVE-2014-0574: Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux…
PriorityP350critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.26%
94.3th percentile
Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 15.0.0.356 | — |
| adobe | air_sdk | <= 15.0.0.356 | — |
| adobe | air_sdk_compiler | < 15.0.0.356 | 15.0.0.356 |
| adobe | flash_player | >= 11.0 < 11.2.202.418 | 11.2.202.418 |
| adobe | flash_player | >= 13.0 < 13.0.0.252 | 13.0.0.252 |
| adobe | flash_player | 14.0 – 14.0.0.179 | — |
| adobe | flash_player | >= 15.0 < 15.0.0.223 | 15.0.0.223 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4367-vj5g-xqcr: Double free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14
CVE-2014-0574 [HIGH] CWE-94 GHSA-4367-vj5g-xqcr: Double free vulnerability in Adobe Flash Player before 13
Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2014-0574: Double free vulnerability in Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-0574 [CRITICAL] CVE-2014-0574: Double free vulnerability in Adobe Flash Player before 13
Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-0574 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
HackerOne
Race condition in Flash workers may cause an exploitable double free
hackerone·2019-11-12·CVSS 10.0
CVE-2014-0574 [CRITICAL] Race condition in Flash workers may cause an exploitable double free
Race condition in Flash workers may cause an exploitable double free
The issue occurs while sharing a bytearray between two workers. If both call bytearray.clear() at the same time, Flash does not correctly handle the race and may double free the array.
Indentified as CVE-2014-0574, and reported to Adobe via Chrome VRP:
http://helpx.adobe.com/security/products/flash-player/apsb14-24.html
Original report with proof of concept:
https://code.google.com/p/chromium/issues/detail?id=423703
Bugzilla
flash-plugin: multiple code execution flaws (APSB14-24)
bugzilla·2014-11-12·CVSS 10.0
CVE-2014-0576 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Adobe has released Flash Player 11.2.202.418 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0576, CVE-2014-0581, CVE-2014-8440, CVE-2014-8441).
* These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2014-0573, CVE-2014-0588, CVE-2014-8438).
* These updates resolve a double free vulnerability that could lead to code execution (CVE-2014-0574).
* These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2014-0577, CVE-2014-0584, CVE-2014-0585, CVE-2014-0586, CVE-2014-0590).
* These updates resolve heap buffer overflow vulnerabilities that could lead to code executi
http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb14-24.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttps://code.google.com/p/chromium/issues/detail?id=423703http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb14-24.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttps://code.google.com/p/chromium/issues/detail?id=423703
2014-11-11
Published