CVE detail
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.
newswww.securityweek.comJan 20, 2017, 4:16 PM- Hacking Team Zero-Day tied to attacks In Korea and JapanSecurity Affairs
Security experts at Trend Micro revealed that one of the exploits discovered in the Hacking Team package tied to Attacks In Korea and Japan. Following the recent hack of the popular surveillance firm Hacking Team, the experts started the analysis of the material leaked online by the attackers. The package leaked online include also a number […]
newssecurityaffairs.comJul 9, 2015, 1:44 PM - Hacking Team’s Flash 0-day exploit used against Korean targets before it was leakedHelp Net Security
The Adobe Flash zero-day (CVE-2015-5119) exploit found in the Hacking Team’s leaked data has already been added to several exploit kits, but Trend Micro researchers have found evidence of it being used before the data was leaked.Flagged by the company’s Smart Protection Network, it was apparently used to compromise a number of South Korean targets and a Japanese one.“In late June, we learned that a user in Korea was the attempted target of various exploits, … More →
newswww.helpnetsecurity.comJul 9, 2015, 3:13 AM - Researchers warn about schemes that lead to FlashPack exploit kitHelp Net Security
Security researchers have spotted two different online schemes that lead to pages hosting the FlashPack exploit kit. The first one relies on users visiting a compromised SourceForge sub-domain, where a JavaScript file redirects them to the website equipped with the exploit kit, which pushes on them a malicious Flash file that exploits a vulnerability to download and install a variant of the Carberp trojan. Malwarebytes’ Jerome Segura doesn’t say how the users are lured or … More →
newswww.helpnetsecurity.comAug 26, 2014, 8:05 AM After analyzing public vulnerabilities and exploit trends in the first half of 2014, Bromium Labs concluded that Internet Explorer is the “sweet spot for attackers.” “Internet Explorer was the most patched and also one of the most exploited products,” the report (pdf) states. Microsoft’s browser “set a record high for reported vulnerabilities in the first […]
newswww.csoonline.comJul 23, 2014, 3:23 PMOn Tuesday afternoon, Adobe released an out-of-band security update to address a critical zero-day security vulnerability in Adobe Flash Player. The remotely exploitable vulnerability is being used in attacks in the wild and allows an attacker to take control of an affected system.
newswww.securityweek.comFeb 5, 2014, 4:48 PMAdobe has released security updates for Adobe Flash Player to fix a critical vulnerability exploited in a sophisticated cyber espionage campaign. Adobe has released today a new patch for the Flash Player product to fix a vulnerability which is currently being exploited. The vulnerability (CVE-2014-0497), allows an attacker to remotely take control of the targeted system […]
newssecurityaffairs.comFeb 4, 2014, 10:02 PMAdobe on Tuesday released an out-of-band security update to address a critical zero-day security vulnerability in Adobe Flash Player that could allow an attacker to remotely take control of an affected system.
newswww.securityweek.comFeb 4, 2014, 6:06 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-4171CVSS 9.8 · Critical
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
KEV listed12 mentions - CVE-2015-5119CVSS 9.8 · Critical
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows…
- CVE-2014-0502CVSS 8.8 · High
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR…
- CVE-2013-2555CVSS 10.0 · Critical
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11…
- CVE-2013-0648CVSS 8.8 · High
Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and be…
KEV listed3 mentions - CVE-2013-0643CVSS 8.8 · High
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, do…