CVE-2014-0502

Confirmed PUBLISHED

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before...

Adobe · Flash Player
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High

At a Glance

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.

nessus_scanner windows macos linux cisa android
CVE Published
Feb 21, 2014
Exploitation Reported
Sep 17, 2024
CVSS
8.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
adobe
flash_player

0 to < 11.7.700.269

Affected
adobe
flash_player

11.8.0 to < 12.0.0.70

Affected
adobe
flash_player

0 to < 11.7.700.269

Affected
adobe
flash_player

11.8.0 to < 12.0.0.70

Affected
adobe
air

0 to < 4.0.0.1628

Affected
adobe
air_sdk

0 to < 4.0.0.1628

Affected
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2014:0278 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015...
  • GLSA-201405-04 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201405-04.xml
  • RHSA-2014:0196 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2014-0196.html
  • SUSE-SU-2014:0290 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017...
  • openSUSE-SU-2014:0277 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014...
Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.