10

CVE-2014-0536

Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version <= 11.2.202.359
   Adobe ≫ Flash Player Version 11.2.202.223
   Adobe ≫ Flash Player Version 11.2.202.228
   Adobe ≫ Flash Player Version 11.2.202.233
   Adobe ≫ Flash Player Version 11.2.202.235
   Adobe ≫ Flash Player Version 11.2.202.236
   Adobe ≫ Flash Player Version 11.2.202.238
   Adobe ≫ Flash Player Version 11.2.202.243
   Adobe ≫ Flash Player Version 11.2.202.251
   Adobe ≫ Flash Player Version 11.2.202.258
   Adobe ≫ Flash Player Version 11.2.202.261
   Adobe ≫ Flash Player Version 11.2.202.262
   Adobe ≫ Flash Player Version 11.2.202.270
   Adobe ≫ Flash Player Version 11.2.202.273
   Adobe ≫ Flash Player Version 11.2.202.275
   Adobe ≫ Flash Player Version 11.2.202.280
   Adobe ≫ Flash Player Version 11.2.202.285
   Adobe ≫ Flash Player Version 11.2.202.291
   Adobe ≫ Flash Player Version 11.2.202.297
   Adobe ≫ Flash Player Version 11.2.202.310
   Adobe ≫ Flash Player Version 11.2.202.332
   Adobe ≫ Flash Player Version 11.2.202.335
   Adobe ≫ Flash Player Version 11.2.202.336
   Adobe ≫ Flash Player Version 11.2.202.341
   Adobe ≫ Flash Player Version 11.2.202.346
   Adobe ≫ Flash Player Version 11.2.202.350
   Adobe ≫ Flash Player Version 11.2.202.356
   Linux ≫ Linux Kernel
Adobe ≫ Flash Player Version <= 13.0.0.214
   Apple ≫ macOS X
   Microsoft ≫ Windows
Adobe ≫ Flash Player Version 13.0.0.182
   Apple ≫ macOS X
   Microsoft ≫ Windows
Adobe ≫ Flash Player Version 13.0.0.201
   Apple ≫ macOS X
   Microsoft ≫ Windows
Adobe ≫ Flash Player Version 13.0.0.206
   Apple ≫ macOS X
   Microsoft ≫ Windows
Adobe ≫ Adobe Air Sdk Version <= 13.0.0.111
Adobe ≫ Adobe Air Sdk Version 13.0.0.83
Adobe ≫ Adobe Air Version <= 13.0.0.111
Adobe ≫ Adobe Air Version 13.0.0.83
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.91% 0.953
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://helpx.adobe.com/security/products/flash-player/apsb14-16.html
Patch
Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00021.html
http://lists.opensuse.org/opensuse-updates/2014-06/msg00029.html
http://lists.opensuse.org/opensuse-updates/2014-06/msg00030.html
http://rhn.redhat.com/errata/RHSA-2014-0745.html
http://secunia.com/advisories/58390
http://secunia.com/advisories/58465
http://secunia.com/advisories/58585
http://secunia.com/advisories/59053
http://secunia.com/advisories/59304
http://security.gentoo.org/glsa/glsa-201406-17.xml
http://www.securitytracker.com/id/1030368
http://www.securityfocus.com/bid/67961