4.3

CVE-2014-0531

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeAdobe Air Version <= 13.0.0.111
AdobeAdobe Air Version13.0.0.83
AdobeFlash Player Version <= 13.0.0.214
   ApplemacOS X
   MicrosoftWindows
AdobeFlash Player Version13.0.0.182
   ApplemacOS X
   MicrosoftWindows
AdobeFlash Player Version13.0.0.201
   ApplemacOS X
   MicrosoftWindows
AdobeFlash Player Version13.0.0.206
   ApplemacOS X
   MicrosoftWindows
AdobeAdobe Air Sdk Version <= 13.0.0.111
AdobeAdobe Air Sdk Version13.0.0.83
AdobeFlash Player Version <= 11.2.202.359
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.223
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.228
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.233
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.235
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.236
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.238
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.243
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.251
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.258
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.261
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.262
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.270
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.273
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.275
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.280
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.285
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.291
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.297
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.310
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.332
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.335
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.336
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.341
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.346
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.350
   LinuxLinux Kernel
AdobeFlash Player Version11.2.202.356
   LinuxLinux Kernel
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.01% 0.764
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.