Junglewise Threat Intelligence

CVE-2014-0497: Adobe Flash Player Integer Underflow Vulnerablity

CVE-2014-0497 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-17

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player contains an integer underflow vulnerability (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability affects multiple versions across Windows, Mac OS X, and Linux platforms.

Affected products

  • Adobe Flash Player before 11.7.700.261
  • Adobe Flash Player 11.8.x through 12.0.x before 12.0.0.44
  • Adobe Flash Player before 11.2.202.336 on Linux

Timeline

  • 2014-02-04: advisory: Adobe released security bulletin APSB14-04
  • 2024-09-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-17: disclosed: NVD publication date

Related threats