10

CVE-2014-0502

Warnung
Exploit
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version < 11.7.700.269
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version >= 11.8.800.94 < 12.0.0.70
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Adobe Air Sdk Version < 4.0.0.1628
Adobe ≫ Flash Player Version < 11.2.202.341
   Linux ≫ Linux Kernel Version -
Adobe ≫ Adobe Air Version < 4.0.0.1628
   Google ≫ Android Version -
Opensuse ≫ Opensuse Version 11.4
Opensuse ≫ Opensuse Version 12.3
Opensuse ≫ Opensuse Version 13.1
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Redhat ≫ Enterprise Linux Eus Version 6.5

17.09.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Adobe Flash Player Double Free Vulnerablity

Schwachstelle

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.

Beschreibung

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 24.2% 0.976
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.

http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
Patch
Vendor Advisory
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html
Mailing List
http://rhn.redhat.com/errata/RHSA-2014-0196.html
Third Party Advisory
http://security.gentoo.org/glsa/glsa-201405-04.xml
Third Party Advisory
http://www.alienvault.com/open-threat-exchange/blog/analysis-of-an-attack-exploiting-the-adobe-zero-day-cve-2014-0502/
Third Party Advisory
Exploit
https://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html
Third Party Advisory
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0502
US Government Resource