CVE-2014-8438
published 2014-11-11CVE-2014-8438: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.93%
95.1th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0573 and CVE-2014-0588.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 15.0.0.356 | — |
| adobe | air_sdk | <= 15.0.0.356 | — |
| adobe | air_sdk_compiler | < 15.0.0.356 | 15.0.0.356 |
| adobe | flash_player | >= 11.0 < 11.2.202.418 | 11.2.202.418 |
| adobe | flash_player | >= 13.0 < 13.0.0.252 | 13.0.0.252 |
| adobe | flash_player | 14.0 – 14.0.0.179 | — |
| adobe | flash_player | >= 15.0 < 15.0.0.223 | 15.0.0.223 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j6vg-p7jc-qx69: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2014-0588 [CRITICAL] GHSA-j6vg-p7jc-qx69: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0573 and CVE-2014-8438.
GHSA
GHSA-g5jh-8j54-9638: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2014-0573 [CRITICAL] GHSA-g5jh-8j54-9638: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0588 and CVE-2014-8438.
GHSA
GHSA-chfm-jp77-g4fc: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2014-8438 [CRITICAL] GHSA-chfm-jp77-g4fc: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0573 and CVE-2014-0588.
OSV
CVE-2014-0573: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-0573 [CRITICAL] CVE-2014-0573: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0588 and CVE-2014-8438.
OSV
CVE-2014-8438: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-8438 [CRITICAL] CVE-2014-8438: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0573 and CVE-2014-0588.
OSV
CVE-2014-0588: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-0588 [CRITICAL] CVE-2014-0588: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0573 and CVE-2014-8438.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-0588 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0573 and CVE-2014-8438.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-0573 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0588 and CVE-2014-8438.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-8438 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0573 and CVE-2014-0588.
No detection rules found.
No public exploits indexed.
HackerOne
Adobe Flash Player MP4 Use-After-Free Vulnerability
hackerone·2015-03-11·CVSS 10.0
[CRITICAL] Adobe Flash Player MP4 Use-After-Free Vulnerability
Adobe Flash Player MP4 Use-After-Free Vulnerability
I. Summary
Adobe Flash Player is prone to a vulnerability which leads to Use-After-Free. After parsing a malformed mp4 file, Flash will not free the NetStream object properly. Such memory block is still accessed even the page containing Flash is closed, which leads to a memory crash.
II. Description
Adobe Flash is a multimedia and software platform used for authoring of vector graphics, animation, games and rich Internet applications (RIAs) that can be viewed, played and executed in Adobe Flash Player. NetStream object can load and play an external mp4 file.
After playing a mp4 file, Flash will keep on accessing the memory saving the media object. A malformed mp4 file will trick the Flash to believe that this film never ends. The accessi
Bugzilla
flash-plugin: multiple code execution flaws (APSB14-24)
bugzilla·2014-11-12·CVSS 10.0
CVE-2014-0576 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Adobe has released Flash Player 11.2.202.418 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0576, CVE-2014-0581, CVE-2014-8440, CVE-2014-8441).
* These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2014-0573, CVE-2014-0588, CVE-2014-8438).
* These updates resolve a double free vulnerability that could lead to code execution (CVE-2014-0574).
* These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2014-0577, CVE-2014-0584, CVE-2014-0585, CVE-2014-0586, CVE-2014-0590).
* These updates resolve heap buffer overflow vulnerabilities that could lead to code executi
http://helpx.adobe.com/security/products/flash-player/apsb14-24.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://www.securityfocus.com/bid/71049https://exchange.xforce.ibmcloud.com/vulnerabilities/98619http://helpx.adobe.com/security/products/flash-player/apsb14-24.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://www.securityfocus.com/bid/71049https://exchange.xforce.ibmcloud.com/vulnerabilities/98619
2014-11-11
Published