CVE-2014-0497
Summary
| CVE | CVE-2014-0497 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-05 05:15:29 UTC |
| Updated | 2026-04-21 21:11:48 UTC |
| Description | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.998830000 probability, percentile 0.999640000 (date 2026-07-22)
CISA KEV: Listed on 2024-09-17; due 2024-10-08; ransomware use Unknown
Problem Types: CWE-191 | n/a | CWE-191 CWE-191 Integer Underflow (Wrap or Wraparound)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Adobe |
|---|---|
| Product | Flash Player |
| Name | Adobe Flash Player Integer Underflow Vulnerablity |
| Required Action | The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. |
| Notes | https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2014-0497 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Flash Player | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | N/a | affected n/a | Not specified |
| ADP | Adobe | Flash Player | affected 11.7.700.261 custom | Not specified |
| ADP | Adobe | Flash Player | affected 12.0.0 12.0.0.44 custom | Not specified |
| ADP | Adobe | Flash Player | affected 11.7.700.261 custom | Not specified |
| ADP | Adobe | Flash Player | affected 12.0.0 12.0.0.44 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA56437 - Google Chrome Flash Player Integer Underflow Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Third Party Advisory |
| Adobe Security Bulletin | af854a3a-2127-422b-91ae-364da2661108 | helpx.adobe.com | Broken Link, Patch, Vendor Advisory |
| [security-announce] openSUSE-SU-2014:0203-1: critical: update flash-play | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| Adobe Flash Player CVE-2014-0497 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Security Advisory SA56737 - Adobe Flash Player Integer Underflow Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Third Party Advisory |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | Release Notes |
| Security Advisory SA56839 - SUSE update for flash-player - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Third Party Advisory |
| Security Advisory SA56799 - Red Hat update for flash-plugin - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Third Party Advisory |
| www.osvdb.org/102849 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| [security-announce] SUSE-SU-2014:0221-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| Security Advisory SA56780 - Microsoft Windows Flash Player Integer Underflow Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2014:0197-1: critical: flash-player to 1 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| Adobe Flash Player Integer Underflow Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Adobe Flash Player Integer Underflow Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2024-09-17T00:00:00.000Z | CVE-2014-0497 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.