CVE-2014-8443Adobe Flash Player vulnerability

7 documents6 sources
Severity
10.0CRITICALNVD
EPSS
10.9%
top 6.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateMay 14

Description

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDadobe/flash_player13.013.0.0.252+3

🔴Vulnerability Details

2
GHSA
GHSA-g2mv-w3jp-4jfv: Use-after-free vulnerability in Adobe Flash Player before 132022-05-14
OSV
CVE-2014-8443: Use-after-free vulnerability in Adobe Flash Player before 132014-12-10

💥Exploits & PoCs

2
Exploit-DB
Ubiquiti UbiFi / mFi / AirVision - Cross-Site Request Forgery2014-07-28
Exploit-DB
Foreman Smart-Proxy - Remote Command Injection2014-06-05

📋Vendor Advisories

1
Red Hat
flash-plugin: Multiple code-execution flaws (APSB14-27)2014-12-09

💬Community

1
Bugzilla
CVE-2014-0587 CVE-2014-9164 CVE-2014-8443 CVE-2014-9163 flash-plugin: Multiple code-execution flaws (APSB14-27)2014-12-10