CVE-2014-5333

Description

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a $ (dollar sign) or ( (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.325

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe Air 14.0.0.137 to latest versionWindows
Upgrade Adobe flash player 14.0.0.145 to latest versionWindows
Multiple vulnerabilities affected in Adobe AIR 14.0.0.137Windows
Multiple vulnerabilities affected in Adobe Flash Player Plugin 14.0.0.145Windows
Multiple vulnerabilities affected in Adobe Flash Player PPAPI 14.0.0.145Windows
Multiple Vulnerabilities are affected in Adobe AIR For Mac 14.0.0.137Mac
Multiple Vulnerabilities are affected in Adobe AIR 13.0.0.111Mac
Multiple Vulnerabilities are affected in Adobe AIR 13.0.0.83Mac
Multiple Vulnerabilities are affected in Adobe AIR 14.0.0.110Mac
Multiple Vulnerabilities are affected in Adobe AIR 14.0.0.137Mac
Multiple Vulnerabilities are affected in Adobe AIR For Mac 13.0.0.111Mac
Multiple Vulnerabilities are affected in Adobe AIR For Mac 13.0.0.83Mac
Multiple Vulnerabilities are affected in Adobe AIR For Mac 14.0.0.110Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234