Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2014-0497
PUBLISHEDInteger underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before...
- Vendor
- Adobe
- Product
- Flash Player
- Published
- Feb 05, 2014
- EPSS
- —
Description
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitation status
Exploited in the wild
Recorded 2024-09-17 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- No
- Technical impact
- total
References
- http://www.exploit-db.com/exploits/33212
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0137.html
- http://www.osvdb.org/102849
- http://www.securityfocus.com/bid/65327
- http://secunia.com/advisories/56799
- http://www.securitytracker.com/id/1029715
- http://secunia.com/advisories/56737
- http://secunia.com/advisories/56437
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
- http://secunia.com/advisories/56780
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
- http://secunia.com/advisories/56839
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Sep 17, 2024 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/adobe_flash_avm2.rb | Apr 28, 2025 |
| Nessus | https://www.tenable.com/plugins/nessus/75246 | Sep 17, 2024 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Nessus
-
Detected by Metasploit