CVE-2014-5333
published 2014-08-19CVE-2014-5333: Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.51%
88.0th percentile
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 14.0.0.137 | — |
| adobe | adobe_air | <= 14.0.0.110 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 14.0.0.137 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | air | <= 18.0.0.199 | — |
| adobe | air | <= 18.0.0.143 | — |
| adobe | air | <= 17.0.0.144 | — |
| adobe | air | <= 17.0.0.172 | — |
| adobe | air_sdk | <= 18.0.0.199 | — |
| adobe | air_sdk | <= 17.0.0.172 | — |
| adobe | air_sdk_compiler | <= 18.0.0.180 | — |
| adobe | air_sdk_compiler | <= 17.0.0.172 | — |
| adobe | flash_player | <= 11.2.202.508 | — |
| adobe | flash_player | <= 13.0.0.289 | — |
| adobe | flash_player | <= 13.0.0.231 | — |
| adobe | flash_player | <= 11.2.202.394 | — |
| adobe | flash_player | <= 11.2.202.460 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: information leaks and hardening bypass fixed in APSB15-23
vendor_redhat·2015-09-21·CVSS 4.3
CVE-2015-5571 [MEDIUM] flash-plugin: information leaks and hardening bypass fixed in APSB15-23
flash-plugin: information leaks and hardening bypass fixed in APSB15-23
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
Red Hat
flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
vendor_redhat·2015-06-09·CVSS 4.3
CVE-2015-3096 [MEDIUM] CWE-352 flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass a CVE-2014-5333 protection mechanism via unspecified vectors.
Red Hat
flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
vendor_redhat·2014-08-12·CVSS 4.3
CVE-2014-5333 [MEDIUM] flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplet
GHSA
GHSA-9rw6-x6f2-42c3: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2015-5571 [MEDIUM] CWE-200 GHSA-9rw6-x6f2-42c3: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
GHSA
GHSA-8qmf-pwhh-phx8: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2015-3096 [MEDIUM] CWE-352 GHSA-8qmf-pwhh-phx8: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass a CVE-2014-5333 protection mechanism via unspecified vectors.
GHSA
GHSA-p4f6-prp8-fmgf: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2014-5333 [MEDIUM] CWE-352 GHSA-p4f6-prp8-fmgf: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.
OSV
CVE-2015-5571: Adobe Flash Player before 18
osv·2015-09-22·CVSS 4.3
CVE-2015-5571 [MEDIUM] CVE-2015-5571: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
OSV
CVE-2015-3096: Adobe Flash Player before 13
osv·2015-06-10·CVSS 4.3
CVE-2015-3096 [MEDIUM] CVE-2015-3096: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass a CVE-2014-5333 protection mechanism via unspecified vectors.
OSV
CVE-2014-5333: Adobe Flash Player before 13
osv·2014-08-19·CVSS 4.3
CVE-2014-5333 [MEDIUM] CVE-2014-5333: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.
No detection rules found.
No public exploits indexed.
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 06-09-2015
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 06-09-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2015-3096 flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
bugzilla·2015-06-10·CVSS 4.3
CVE-2015-3096 [MEDIUM] CVE-2015-3096 flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
CVE-2015-3096 flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
Adobe Security Bulletin APSB15-11 for Adobe Flash Player describes a flaw that could be exploited to bypass the fix for CVE-2014-5333.
Quoting from the APSB15-11:
These updates resolve a vulnerability (CVE-2015-3096) that could be exploited to bypass the fix for CVE-2014-5333.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-11.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1086 https://rhn.redhat.com/errata/RHSA-2015-1086.html
Bugzilla
CVE-2014-0538 CVE-2014-0540 CVE-2014-0541 CVE-2014-0542 CVE-2014-0543 CVE-2014-0544 CVE-2014-0545 CVE-2014-5333 flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
bugzilla·2014-08-12·CVSS 10.0
CVE-2014-0538 [CRITICAL] CVE-2014-0538 CVE-2014-0540 CVE-2014-0541 CVE-2014-0542 CVE-2014-0543 CVE-2014-0544 CVE-2014-0545 CVE-2014-5333 flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
CVE-2014-0538 CVE-2014-0540 CVE-2014-0541 CVE-2014-0542 CVE-2014-0543 CVE-2014-0544 CVE-2014-0545 CVE-2014-5333 flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
Adobe has released Flash Player 11.2.202.400 for Linux to correct the following flaws:
* These updates resolve memory leakage vulnerabilities that could be used to bypass memory address randomization (CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, CVE-2014-0545).
* These updates resolve a security bypass vulnerability (CVE-2014-0541).
* These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2014-0538).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-18.html
Discussion:
This issue has been addressed in following pro
http://helpx.adobe.com/security/products/flash-player/apsb14-18.htmlhttp://miki.it/blog/2014/8/15/adobe-really-fixed-rosetta-flash-today/https://exchange.xforce.ibmcloud.com/vulnerabilities/95418http://helpx.adobe.com/security/products/flash-player/apsb14-18.htmlhttp://miki.it/blog/2014/8/15/adobe-really-fixed-rosetta-flash-today/https://exchange.xforce.ibmcloud.com/vulnerabilities/95418
2014-08-19
Published