Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title Adobe Flash Player: Multiple vulnerabilities
Informations
Name GLSA-201405-04 First vendor Publication 2014-05-03
Vendor Gentoo Last vendor Modification 2014-05-03
Severity (Vendor) Normal Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Synopsis

Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in execution of arbitrary code.

Background

The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites.

Description

Multiple vulnerabilities have been discovered in Adobe Flash Player.
Please review the CVE identifiers referenced below for details.

Impact

A remote attacker could entice a user to open a specially crafted SWF file using Adobe Flash Player, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Furthermore, a remote attacker may be able to bypass the Same Origin Policy or read the clipboard via unspecified vectors.

Workaround

There is no known workaround at this time.

Resolution

All Adobe Flash Player users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.356"

References

[ 1 ] CVE-2014-0498 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0498
[ 2 ] CVE-2014-0499 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0499
[ 3 ] CVE-2014-0502 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0502
[ 4 ] CVE-2014-0503 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0503
[ 5 ] CVE-2014-0504 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0504
[ 6 ] CVE-2014-0506 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0506
[ 7 ] CVE-2014-0507 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0507
[ 8 ] CVE-2014-0508 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0508
[ 9 ] CVE-2014-0509 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0509
[ 10 ] CVE-2014-0515 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0515

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-201405-04.xml

Original Source

Url : http://security.gentoo.org/glsa/glsa-201405-04.xml

CWE : Common Weakness Enumeration

% Id Name
30 % CWE-264 Permissions, Privileges, and Access Controls
30 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
20 % CWE-399 Resource Management Errors
10 % CWE-200 Information Exposure
10 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:22099
 
Oval ID: oval:org.mitre.oval:def:22099
Title: Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Description: Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0503
Version: 9
Platform(s): Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows 8
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows Server 2003
Microsoft Windows XP
Microsoft Windows Server 2012 R2
Product(s): Adobe Flash Player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22171
 
Oval ID: oval:org.mitre.oval:def:22171
Title: Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows allows attackers to read the clipboard via unspecified vectors.
Description: Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows attackers to read the clipboard via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0504
Version: 9
Platform(s): Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows 8
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows Server 2003
Microsoft Windows XP
Microsoft Windows Server 2012 R2
Product(s): Adobe Flash Player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22201
 
Oval ID: oval:org.mitre.oval:def:22201
Title: Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK and Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors
Description: Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0502
Version: 12
Platform(s): Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows 8
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s): Adobe Flash Player
Adobe AIR
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22445
 
Oval ID: oval:org.mitre.oval:def:22445
Title: Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK and Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
Description: Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0499
Version: 12
Platform(s): Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows 8
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s): Adobe Flash Player
Adobe AIR
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22568
 
Oval ID: oval:org.mitre.oval:def:22568
Title: Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK and Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified vectors
Description: Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0498
Version: 12
Platform(s): Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows 8
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s): Adobe Flash Player
Adobe AIR
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23209
 
Oval ID: oval:org.mitre.oval:def:23209
Title: ELSA-2014:0196: flash-plugin security update (Critical)
Description: Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
Family: unix Class: patch
Reference(s): ELSA-2014:0196-00
CVE-2014-0498
CVE-2014-0499
CVE-2014-0502
Version: 17
Platform(s): Oracle Linux 6
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23928
 
Oval ID: oval:org.mitre.oval:def:23928
Title: RHSA-2014:0289: flash-plugin security update (Moderate)
Description: Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows attackers to read the clipboard via unspecified vectors.
Family: unix Class: patch
Reference(s): RHSA-2014:0289-00
CVE-2014-0503
CVE-2014-0504
Version: 9
Platform(s): Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23994
 
Oval ID: oval:org.mitre.oval:def:23994
Title: DEPRECATED: ELSA-2014:0447: flash-plugin security update (Critical)
Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed in the References section. A flaw was found in the way flash-plugin displayed certain SWF content. An attacker could use this flaw to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2014-0515) All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 11.2.202.356.
Family: unix Class: patch
Reference(s): ELSA-2014:0447-00
CVE-2014-0515
Version: 5
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24148
 
Oval ID: oval:org.mitre.oval:def:24148
Title: ELSA-2014:0447: flash-plugin security update (Critical)
Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed in the References section. A flaw was found in the way flash-plugin displayed certain SWF content. An attacker could use this flaw to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2014-0515) All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 11.2.202.356.
Family: unix Class: patch
Reference(s): ELSA-2014:0447-00
CVE-2014-0515
Version: 5
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24162
 
Oval ID: oval:org.mitre.oval:def:24162
Title: RHSA-2014:0196: flash-plugin security update (Critical)
Description: Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
Family: unix Class: patch
Reference(s): RHSA-2014:0196-00
CVE-2014-0498
CVE-2014-0499
CVE-2014-0502
Version: 18
Platform(s): Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24315
 
Oval ID: oval:org.mitre.oval:def:24315
Title: ELSA-2014:0289: flash-plugin security update (Moderate)
Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes two vulnerabilities in Adobe Flash Player. These vulnerabilities are detailed in the Adobe Security bulletin APSB14-08, listed in the References section. A vulnerability was reported that could be used to bypass the same origin policy. (CVE-2014-0503) A vulnerability was reported that could be used to read the contents of the clipboard. (CVE-2014-0504) All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 11.2.202.346.
Family: unix Class: patch
Reference(s): ELSA-2014:0289-00
CVE-2014-0503
CVE-2014-0504
Version: 6
Platform(s): Oracle Linux 6
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24368
 
Oval ID: oval:org.mitre.oval:def:24368
Title: Cross-site scripting vulnerability in Adobe Flash Player which less then 12.0.0.77 and less then 11.7.700.275 and Adobe AIR before 13.0.0.83
Description: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0509
Version: 9
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Adobe Flash Player
Adobe AIR
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24439
 
Oval ID: oval:org.mitre.oval:def:24439
Title: RHSA-2014:0380: flash-plugin security update (Critical)
Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes multiple vulnerabilities in Adobe Flash Player. These vulnerabilities are detailed in the Adobe Security Bulletin APSB14-09, listed in the References section. Two flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2014-0506, CVE-2014-0507) A flaw in flash-plugin could allow an attacker to obtain sensitive information if a victim were tricked into visiting a specially crafted web page. (CVE-2014-0508) A flaw in flash-plugin could allow an attacker to conduct cross-site scripting (XSS) attacks if a victim were tricked into visiting a specially crafted web page. (CVE-2014-0509) All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 11.2.202.350.
Family: unix Class: patch
Reference(s): RHSA-2014:0380-00
CVE-2014-0506
CVE-2014-0507
CVE-2014-0508
CVE-2014-0509
Version: 5
Platform(s): Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24561
 
Oval ID: oval:org.mitre.oval:def:24561
Title: Vulnerability in Adobe Flash Player which less then 12.0.0.77 and less then 11.7.700.275 and Adobe AIR before 13.0.0.83
Description: Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0508
Version: 9
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Adobe Flash Player
Adobe AIR
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24613
 
Oval ID: oval:org.mitre.oval:def:24613
Title: Buffer overflow vulnerability in Adobe Flash Player which less then 12.0.0.77 and less then 11.7.700.275 and Adobe AIR before 13.0.0.83
Description: Buffer overflow in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows attackers to execute arbitrary code via unspecified vectors.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0507
Version: 9
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Adobe Flash Player
Adobe AIR
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24647
 
Oval ID: oval:org.mitre.oval:def:24647
Title: ELSA-2014:0380: flash-plugin security update (Critical)
Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes multiple vulnerabilities in Adobe Flash Player. These vulnerabilities are detailed in the Adobe Security Bulletin APSB14-09, listed in the References section. Two flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2014-0506, CVE-2014-0507) A flaw in flash-plugin could allow an attacker to obtain sensitive information if a victim were tricked into visiting a specially crafted web page. (CVE-2014-0508) A flaw in flash-plugin could allow an attacker to conduct cross-site scripting (XSS) attacks if a victim were tricked into visiting a specially crafted web page. (CVE-2014-0509) All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 11.2.202.350.
Family: unix Class: patch
Reference(s): ELSA-2014:0380-00
CVE-2014-0506
CVE-2014-0507
CVE-2014-0508
CVE-2014-0509
Version: 5
Platform(s): Oracle Linux 6
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24650
 
Oval ID: oval:org.mitre.oval:def:24650
Title: RHSA-2014:0447: flash-plugin security update (Critical)
Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed in the References section. A flaw was found in the way flash-plugin displayed certain SWF content. An attacker could use this flaw to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2014-0515) All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 11.2.202.356.
Family: unix Class: patch
Reference(s): RHSA-2014:0447-00
CVE-2014-0515
Version: 3
Platform(s): Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Product(s): flash-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24657
 
Oval ID: oval:org.mitre.oval:def:24657
Title: Use-after-free vulnerability in Adobe Flash Player which less then 12.0.0.77 and less then 11.7.700.275 and Adobe AIR before 13.0.0.83
Description: Use-after-free vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to execute arbitrary code, and possibly bypass an Internet Explorer sandbox protection mechanism, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0506
Version: 9
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Adobe Flash Player
Adobe AIR
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24683
 
Oval ID: oval:org.mitre.oval:def:24683
Title: Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
Description: Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
Family: windows Class: vulnerability
Reference(s): CVE-2014-0515
Version: 8
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Adobe Flash Player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24868
 
Oval ID: oval:org.mitre.oval:def:24868
Title: SUSE-SU-2014:0605-1 -- Security update for flash-player
Description: This flash-player update to version 11.2.202.356 fixes the following critical security issue: * bnc#875577: buffer overflow vulnerability that leads to arbitrary code execution (CVE-2014-0515) Adobe Security Bulletin (APSB14-13) http://helpx.adobe.com/security/products/flash-player/apsb14 -13.html <http://helpx.adobe.com/security/products/flash-player/apsb1 4-13.html> Security Issue reference: * CVE-2014-0515 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0515 >
Family: unix Class: patch
Reference(s): SUSE-SU-2014:0605-1
CVE-2014-0515
Version: 3
Platform(s): SUSE Linux Enterprise Desktop 11
Product(s): flash-player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:25399
 
Oval ID: oval:org.mitre.oval:def:25399
Title: SUSE-SU-2014:0290-1 -- Security update for flash-player
Description: This update of Adobe Flash Player fixes the following issues: * A stack overflow vulnerability that could have resulted in arbitrary code execution. (CVE-2014-0498) * A memory leak vulnerability that could have been used to defeat memory address layout randomization. (CVE-2014-0499) * A double free vulnerability that could have resulted in arbitrary code execution. (CVE-2014-0502)
Family: unix Class: patch
Reference(s): SUSE-SU-2014:0290-1
CVE-2014-0498
CVE-2014-0499
CVE-2014-0502
Version: 3
Platform(s): SUSE Linux Enterprise Desktop 11
Product(s): flash-player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:25512
 
Oval ID: oval:org.mitre.oval:def:25512
Title: SUSE-SU-2014:0387-1 -- Security update for flash-player
Description: Adobe Flash Player was updated to version 11.2.202.346 to fix security issues.
Family: unix Class: patch
Reference(s): SUSE-SU-2014:0387-1
CVE-2014-0503
CVE-2014-0504
Version: 3
Platform(s): SUSE Linux Enterprise Desktop 11
Product(s): flash-player
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:25532
 
Oval ID: oval:org.mitre.oval:def:25532
Title: SUSE-SU-2014:0535-1 -- Security update for flash-player
Description: Adobe flash-player has been updated to version 11.2.202.350 to resolve security issues and bugs. More information can be found at http://helpx.adobe.com/security/products/flash-player/apsb14 -09.html <http://helpx.adobe.com/security/products/flash-player/apsb1 4-09.html> The following security issues have been fixed: * a use-after-free vulnerability that could have resulted in arbitrary code execution (CVE-2014-0506). * a buffer overflow vulnerability that could have resulted in arbitrary code execution (CVE-2014-0507). * a security bypass vulnerability that could have lead to information disclosure (CVE-2014-0508). * a cross-site-scripting vulnerability (CVE-2014-0509).
Family: unix Class: patch
Reference(s): SUSE-SU-2014:0535-1
CVE-2014-0506
CVE-2014-0507
CVE-2014-0508
CVE-2014-0509
Version: 3
Platform(s): SUSE Linux Enterprise Desktop 11
Product(s): flash-player
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 59
Application 23
Application 311

SAINT Exploits

Description Link
Adobe Pixel Shader More info here

ExploitDB Exploits

id Description
2014-05-12 Adobe Flash Player Shader Buffer Overflow

Information Assurance Vulnerability Management (IAVM)

Date Description
2014-05-01 IAVM : 2014-A-0060 - Adobe Flash Player Buffer Overflow Vulnerability
Severity : Category I - VMSKEY : V0050013
2014-04-10 IAVM : 2014-A-0047 - Multiple Vulnerabilities in Adobe Flash Player and AIR
Severity : Category I - VMSKEY : V0048681
2014-03-13 IAVM : 2014-A-0034 - Multiple Vulnerabilities in Adobe Flash Player
Severity : Category I - VMSKEY : V0046181
2014-02-27 IAVM : 2014-A-0029 - Multiple Vulnerabilities in Adobe Flash Player and AIR
Severity : Category I - VMSKEY : V0044537

Snort® IPS/IDS

Date Description
2016-04-05 Adobe Flash pixel bender buffer overflow attempt
RuleID : 37940 - Revision : 2 - Type : FILE-MULTIMEDIA
2016-04-05 Adobe Flash pixel bender buffer overflow attempt
RuleID : 37939 - Revision : 3 - Type : FILE-MULTIMEDIA
2016-04-05 Adobe Flash pixel bender buffer overflow attempt
RuleID : 37938 - Revision : 3 - Type : FILE-MULTIMEDIA
2016-04-05 Adobe Flash pixel bender buffer overflow attempt
RuleID : 37937 - Revision : 2 - Type : FILE-MULTIMEDIA
2016-03-18 Adobe Flash Player worker shared object user-after-free attempt
RuleID : 37685 - Revision : 2 - Type : FILE-FLASH
2016-03-18 Adobe Flash Player worker shared object user-after-free attempt
RuleID : 37684 - Revision : 2 - Type : FILE-FLASH
2015-04-30 Nuclear exploit kit obfuscated file download
RuleID : 33983 - Revision : 5 - Type : EXPLOIT-KIT
2015-04-30 Nuclear exploit kit landing page detected
RuleID : 33982 - Revision : 3 - Type : EXPLOIT-KIT
2015-04-30 Nuclear exploit kit flash file download
RuleID : 33981 - Revision : 4 - Type : EXPLOIT-KIT
2014-12-02 Adobe Flash Player worker shared object use-after-free attempt
RuleID : 32360 - Revision : 4 - Type : FILE-FLASH
2014-12-02 Adobe Flash Player worker shared object use-after-free attempt
RuleID : 32359 - Revision : 8 - Type : FILE-FLASH
2014-09-23 Astrum exploit kit Adobe Flash exploit payload request
RuleID : 31968-community - Revision : 1 - Type : EXPLOIT-KIT
2014-11-16 Astrum exploit kit Adobe Flash exploit payload request
RuleID : 31968 - Revision : 2 - Type : EXPLOIT-KIT
2014-11-16 Adobe Flash pixel bender buffer overflow attempt
RuleID : 31524 - Revision : 3 - Type : FILE-MULTIMEDIA
2014-11-16 Adobe Flash pixel bender buffer overflow attempt
RuleID : 31523 - Revision : 3 - Type : FILE-MULTIMEDIA
2014-11-16 Adobe Flash pixel bender buffer overflow attempt
RuleID : 31522 - Revision : 3 - Type : FILE-MULTIMEDIA
2014-11-16 Adobe Flash pixel bender buffer overflow attempt
RuleID : 31521 - Revision : 4 - Type : FILE-MULTIMEDIA
2014-11-16 Adobe Flash pixel bender buffer overflow attempt
RuleID : 31520 - Revision : 3 - Type : FILE-MULTIMEDIA
2014-11-16 Adobe Flash pixel bender buffer overflow attempt
RuleID : 31519 - Revision : 4 - Type : FILE-MULTIMEDIA
2014-11-16 CottonCastle exploit kit decryption page outbound request
RuleID : 31279 - Revision : 3 - Type : EXPLOIT-KIT
2014-11-16 CottonCastle exploit kit Adobe flash outbound connection
RuleID : 31276 - Revision : 4 - Type : EXPLOIT-KIT
2014-05-28 Adobe Flash pixel bender buffer overflow attempt
RuleID : 30877 - Revision : 5 - Type : FILE-MULTIMEDIA
2014-05-28 Adobe Flash pixel bender buffer overflow attempt
RuleID : 30876 - Revision : 4 - Type : FILE-MULTIMEDIA
2014-05-28 Adobe Flash Player SWF ActionScript exploit attempt
RuleID : 30846 - Revision : 3 - Type : FILE-FLASH
2014-05-28 Adobe Flash Player SWF ActionScript exploit attempt
RuleID : 30845 - Revision : 3 - Type : FILE-FLASH
2014-05-28 Adobe Acrobat Reader cross-site scripting attempt
RuleID : 30844 - Revision : 3 - Type : FILE-FLASH
2014-05-28 Adobe Acrobat Reader cross-site scripting attempt
RuleID : 30843 - Revision : 3 - Type : FILE-FLASH
2014-05-15 Adobe Flash Player navigateToUrl hidden channel to file creation
RuleID : 30540 - Revision : 3 - Type : FILE-FLASH
2014-05-15 Adobe Flash Player navigateToUrl hidden channel to file creation
RuleID : 30539 - Revision : 2 - Type : FILE-FLASH
2014-05-15 Adobe Flash Player malformed HTML text null dereference attempt
RuleID : 30538 - Revision : 3 - Type : FILE-FLASH
2014-05-15 Adobe Flash Player malformed HTML text null dereference attempt
RuleID : 30537 - Revision : 3 - Type : FILE-FLASH
2014-05-15 Adobe Flash Player malformed HTML text null dereference attempt
RuleID : 30536 - Revision : 2 - Type : FILE-FLASH
2014-05-15 Adobe Flash Player malformed HTML text null dereference attempt
RuleID : 30535 - Revision : 3 - Type : FILE-FLASH
2014-04-10 Adobe Flash incorrect null uri character normalization attempt
RuleID : 30149 - Revision : 3 - Type : FILE-FLASH
2014-04-10 Adobe Flash incorrect null uri character normalization attempt
RuleID : 30148 - Revision : 3 - Type : FILE-FLASH
2014-04-10 Adobe Flash incorrect null uri character normalization attempt
RuleID : 30147 - Revision : 3 - Type : FILE-FLASH
2014-04-10 Adobe Flash incorrect null uri character normalization attempt
RuleID : 30146 - Revision : 3 - Type : FILE-FLASH
2014-03-29 Adobe Flash Player PCRE regexp out of bounds memory leak ASLR bypass attempt
RuleID : 29984 - Revision : 2 - Type : FILE-FLASH
2014-03-29 Adobe Flash Player PCRE regexp out of bounds memory leak ASLR bypass attempt
RuleID : 29983 - Revision : 3 - Type : FILE-FLASH
2014-03-27 Adobe Flash regular expression grouping depth buffer overflow attempt
RuleID : 29934 - Revision : 4 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player PCRE regexp out of bounds memory leak ASLR bypass attempt
RuleID : 29933 - Revision : 4 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player PCRE regexp out of bounds memory leak ASLR bypass attempt
RuleID : 29932 - Revision : 3 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player worker shared object use-after-free attempt
RuleID : 29931 - Revision : 6 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player worker shared object use-after-free attempt
RuleID : 29930 - Revision : 6 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player worker shared object use-after-free attempt
RuleID : 29929 - Revision : 7 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player worker shared object use-after-free attempt
RuleID : 29928 - Revision : 6 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player buffer overflow attempt
RuleID : 29927 - Revision : 2 - Type : FILE-FLASH
2014-03-27 Adobe Flash Player buffer overflow attempt
RuleID : 29926 - Revision : 3 - Type : FILE-FLASH
2014-01-10 Adobe Flash regular expression grouping depth buffer overflow attempt
RuleID : 19685 - Revision : 13 - Type : FILE-FLASH

Nessus® Vulnerability Scanner

Date Description
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2014-322.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2014-307.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2014-212.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2014-157.nasl - Type : ACT_GATHER_INFO
2014-05-05 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201405-04.nasl - Type : ACT_GATHER_INFO
2014-05-03 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_flash-player-140429.nasl - Type : ACT_GATHER_INFO
2014-04-30 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2014-0447.nasl - Type : ACT_GATHER_INFO
2014-04-28 Name : The remote host has an ActiveX control installed that is affected by a buffer...
File : smb_kb2961887.nasl - Type : ACT_GATHER_INFO
2014-04-28 Name : The remote Mac OS X host has a browser plugin that is affected by a buffer ov...
File : macosx_flash_player_13_0_0_206.nasl - Type : ACT_GATHER_INFO
2014-04-28 Name : The remote Windows host has a browser plugin that is affected by a buffer ove...
File : flash_player_apsb14-13.nasl - Type : ACT_GATHER_INFO
2014-04-25 Name : The remote Mac OS X host contains a web browser that is affected by multiple ...
File : macosx_google_chrome_34_0_1847_131.nasl - Type : ACT_GATHER_INFO
2014-04-25 Name : The remote host contains a web browser that is affected by multiple vulnerabi...
File : google_chrome_34_0_1847_131.nasl - Type : ACT_GATHER_INFO
2014-04-17 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_flash-player-140411.nasl - Type : ACT_GATHER_INFO
2014-04-10 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2014-0380.nasl - Type : ACT_GATHER_INFO
2014-04-09 Name : The remote Mac OS X host contains a version of Adobe AIR that is affected by ...
File : macosx_adobe_air_13_0_0_83.nasl - Type : ACT_GATHER_INFO
2014-04-09 Name : The remote Mac OS X host has a browser plugin that is affected by multiple vu...
File : macosx_flash_player_13_0_0_182.nasl - Type : ACT_GATHER_INFO
2014-04-09 Name : The remote Windows host has a browser plugin that is affected by multiple vul...
File : flash_player_apsb14-09.nasl - Type : ACT_GATHER_INFO
2014-04-09 Name : The remote Windows host contains a version of Adobe AIR that is affected by m...
File : adobe_air_apsb14-09.nasl - Type : ACT_GATHER_INFO
2014-04-08 Name : The remote host has an ActiveX control installed that is affected by multiple...
File : smb_kb2942844.nasl - Type : ACT_GATHER_INFO
2014-04-08 Name : The remote Mac OS X host contains a web browser that is affected by multiple ...
File : macosx_google_chrome_34_0_1847_116.nasl - Type : ACT_GATHER_INFO
2014-04-08 Name : The remote host contains a web browser that is affected by multiple vulnerabi...
File : google_chrome_34_0_1847_116.nasl - Type : ACT_GATHER_INFO
2014-03-18 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_flash-player-140313.nasl - Type : ACT_GATHER_INFO
2014-03-13 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2014-0289.nasl - Type : ACT_GATHER_INFO
2014-03-11 Name : The remote host has an ActiveX control installed that is affected by multiple...
File : smb_kb2938527.nasl - Type : ACT_GATHER_INFO
2014-03-11 Name : The remote Mac OS X host has a browser plugin that is affected by multiple vu...
File : macosx_flash_player_12_0_0_77.nasl - Type : ACT_GATHER_INFO
2014-03-11 Name : The remote Windows host has a browser plugin that is affected by multiple vul...
File : flash_player_apsb14-08.nasl - Type : ACT_GATHER_INFO
2014-02-26 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_flash-player-140224.nasl - Type : ACT_GATHER_INFO
2014-02-23 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2014-0196.nasl - Type : ACT_GATHER_INFO
2014-02-20 Name : The remote Windows host has a browser plugin that is affected by multiple vul...
File : flash_player_apsb14-07.nasl - Type : ACT_GATHER_INFO
2014-02-20 Name : The remote host has an ActiveX control installed that is affected by multiple...
File : smb_kb2934802.nasl - Type : ACT_GATHER_INFO
2014-02-20 Name : The remote Mac OS X host has a browser plugin that is affected by multiple vu...
File : macosx_flash_player_12_0_0_70.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-05-06 13:25:50
  • Multiple Updates
2014-05-03 21:20:06
  • First insertion