10

CVE-2014-9163

Warning

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

Data is provided by the National Vulnerability Database (NVD)
AdobeFlash Player Version >= 13.0 < 13.0.0.259
   ApplemacOS X
   MicrosoftWindows
AdobeFlash Player Version >= 14.0 <= 14.0.0.179
   ApplemacOS X
   MicrosoftWindows
AdobeFlash Player Version >= 15.0 < 15.0.0.246
   ApplemacOS X
   MicrosoftWindows
AdobeFlash Player Version >= 11.0 < 11.2.202.425
   LinuxLinux Kernel

13.04.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

Vulnerability

Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

Description

The impacted product is end-of-life and should be disconnected if still in use.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 12.84% 0.936
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).