4.3
CVE-2014-0509
- EPSS 0.58%
- Published 08.04.2014 23:55:06
- Last modified 12.04.2025 10:46:40
- Source psirt@adobe.com
- Teams watchlist Login
- Open Login
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Data is provided by the National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version <= 11.2.202.346
Adobe ≫ Flash Player Version11.0
Adobe ≫ Flash Player Version11.0.1.152
Adobe ≫ Flash Player Version11.0.1.153
Adobe ≫ Flash Player Version11.1
Adobe ≫ Flash Player Version11.1.102.55
Adobe ≫ Flash Player Version11.1.102.59
Adobe ≫ Flash Player Version11.1.102.62
Adobe ≫ Flash Player Version11.1.102.63
Adobe ≫ Flash Player Version11.1.111.8
Adobe ≫ Flash Player Version11.1.111.44
Adobe ≫ Flash Player Version11.1.111.50
Adobe ≫ Flash Player Version11.1.111.54
Adobe ≫ Flash Player Version11.1.115.7
Adobe ≫ Flash Player Version11.1.115.34
Adobe ≫ Flash Player Version11.1.115.48
Adobe ≫ Flash Player Version11.1.115.54
Adobe ≫ Flash Player Version11.1.115.58
Adobe ≫ Flash Player Version11.2.202.223
Adobe ≫ Flash Player Version11.2.202.228
Adobe ≫ Flash Player Version11.2.202.233
Adobe ≫ Flash Player Version11.2.202.235
Adobe ≫ Flash Player Version11.2.202.236
Adobe ≫ Flash Player Version11.2.202.238
Adobe ≫ Flash Player Version11.2.202.243
Adobe ≫ Flash Player Version11.2.202.251
Adobe ≫ Flash Player Version11.2.202.258
Adobe ≫ Flash Player Version11.2.202.261
Adobe ≫ Flash Player Version11.2.202.262
Adobe ≫ Flash Player Version11.2.202.270
Adobe ≫ Flash Player Version11.2.202.273
Adobe ≫ Flash Player Version11.2.202.275
Adobe ≫ Flash Player Version11.2.202.280
Adobe ≫ Flash Player Version11.2.202.285
Adobe ≫ Flash Player Version11.2.202.291
Adobe ≫ Flash Player Version11.2.202.297
Adobe ≫ Flash Player Version11.2.202.310
Adobe ≫ Flash Player Version11.2.202.327
Adobe ≫ Flash Player Version11.2.202.332
Adobe ≫ Flash Player Version11.2.202.335
Adobe ≫ Flash Player Version11.2.202.336
Adobe ≫ Flash Player Version11.2.202.341
Adobe ≫ Adobe Air Sdk Version <= 4.0.0.1628
Adobe ≫ Adobe Air Sdk Version3.0.0.4080
Adobe ≫ Adobe Air Sdk Version3.1.0.488
Adobe ≫ Adobe Air Sdk Version3.2.0.2070
Adobe ≫ Adobe Air Sdk Version3.3.0.3650
Adobe ≫ Adobe Air Sdk Version3.3.0.3690
Adobe ≫ Adobe Air Sdk Version3.4.0.2540
Adobe ≫ Adobe Air Sdk Version3.4.0.2710
Adobe ≫ Adobe Air Sdk Version3.5.0.600
Adobe ≫ Adobe Air Sdk Version3.5.0.880
Adobe ≫ Adobe Air Sdk Version3.5.0.890
Adobe ≫ Adobe Air Sdk Version3.5.0.1060
Adobe ≫ Adobe Air Sdk Version3.6.0.599
Adobe ≫ Adobe Air Sdk Version3.6.0.6090
Adobe ≫ Adobe Air Sdk Version3.7.0.1530
Adobe ≫ Adobe Air Sdk Version3.7.0.1860
Adobe ≫ Adobe Air Sdk Version3.7.0.2090
Adobe ≫ Adobe Air Sdk Version3.8.0.870
Adobe ≫ Adobe Air Sdk Version3.8.0.910
Adobe ≫ Adobe Air Sdk Version3.8.0.1430
Adobe ≫ Adobe Air Sdk Version3.9.0.1030
Adobe ≫ Adobe Air Sdk Version3.9.0.1210
Adobe ≫ Adobe Air Sdk Version3.9.0.1380
Adobe ≫ Adobe Air Sdk Version4.0.0.1390
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.58% | 0.682 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.