Skip to main content

CVE detail

CVE-2014-0497

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 9.8 · CriticalBuzz score 56.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 56.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • Security experts at Trend Micro revealed that one of the exploits discovered in the Hacking Team package tied to Attacks In Korea and Japan. Following the recent hack of the popular surveillance firm Hacking Team, the experts started the analysis of the material leaked online by the attackers. The package leaked online include also a number […]

    newssecurityaffairs.comJul 9, 2015, 1:44 PM
  • The Adobe Flash zero-day (CVE-2015-5119) exploit found in the Hacking Team’s leaked data has already been added to several exploit kits, but Trend Micro researchers have found evidence of it being used before the data was leaked.Flagged by the company’s Smart Protection Network, it was apparently used to compromise a number of South Korean targets and a Japanese one.“In late June, we learned that a user in Korea was the attempted target of various exploits, … More →

    newswww.helpnetsecurity.comJul 9, 2015, 3:13 AM
  • Security researchers have spotted two different online schemes that lead to pages hosting the FlashPack exploit kit. The first one relies on users visiting a compromised SourceForge sub-domain, where a JavaScript file redirects them to the website equipped with the exploit kit, which pushes on them a malicious Flash file that exploits a vulnerability to download and install a variant of the Carberp trojan. Malwarebytes’ Jerome Segura doesn’t say how the users are lured or … More →

    newswww.helpnetsecurity.comAug 26, 2014, 8:05 AM
  • After analyzing public vulnerabilities and exploit trends in the first half of 2014, Bromium Labs concluded that Internet Explorer is the “sweet spot for attackers.” “Internet Explorer was the most patched and also one of the most exploited products,” the report (pdf) states. Microsoft’s browser “set a record high for reported vulnerabilities in the first […]

    newswww.csoonline.comJul 23, 2014, 3:23 PM
  • On Tuesday afternoon, Adobe released an out-of-band security update to address a critical zero-day security vulnerability in Adobe Flash Player. The remotely exploitable vulnerability is being used in attacks in the wild and allows an attacker to take control of an affected system.

    newswww.securityweek.comFeb 5, 2014, 4:48 PM
  • Adobe has released security updates for Adobe Flash Player to fix a critical vulnerability exploited in a sophisticated cyber espionage campaign. Adobe has released today a new patch for the Flash Player product to fix a vulnerability which is currently being exploited. The vulnerability (CVE-2014-0497), allows an attacker to remotely take control of the targeted system […]

    newssecurityaffairs.comFeb 4, 2014, 10:02 PM
  • Adobe on Tuesday released an out-of-band security update to address a critical zero-day security vulnerability in Adobe Flash Player that could allow an attacker to remotely take control of an affected system.

    newswww.securityweek.comFeb 4, 2014, 6:06 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence