CVE-2014-0492

Description

Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an address leak.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.215

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe Air 3.9.0.1380 to latest versionWindows
Upgrade Adobe flash player 11.9.900.170 to latest versionWindows
Vulnerabilities CVE-2014-0491,CVE-2014-0492 are affected in Adobe AIR 3.9.0.1380Windows
Vulnerabilities CVE-2014-0491,CVE-2014-0492 are affected in Adobe Flash Player Plugin 11.9.900.170Windows
Vulnerabilities CVE-2014-0491,CVE-2014-0492 are affected in Adobe Flash Player PPAPI 11.9.900.170Windows
Vulnerabilities CVE-2014-0491,CVE-2014-0492 are affected in Adobe AIR 4.0.0.1389Windows
Vulnerabilities CVE-2014-0491,CVE-2014-0492 are affected in Adobe AIR For Mac 4.0.0.1389Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234