{"api_version":"1","generated_at":"2026-07-24T20:42:15+00:00","cve":"CVE-2014-0515","urls":{"html":"https://cve.report/CVE-2014-0515","api":"https://cve.report/api/cve/CVE-2014-0515.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-0515","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-0515"},"summary":{"title":"CVE-2014-0515","description":"Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.","state":"PUBLISHED","assigner":"adobe","published_at":"2014-04-29 10:37:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2014-0447.html","name":"http://rhn.redhat.com/errata/RHSA-2014-0447.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030155","name":"http://www.securitytracker.com/id/1030155","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Adobe Flash Player Buffer Overflow Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2014:0605-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-201405-04.xml","name":"http://security.gentoo.org/glsa/glsa-201405-04.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  Adobe Flash Player: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://helpx.adobe.com/security/products/flash-player/apsb14-13.html","name":"http://helpx.adobe.com/security/products/flash-player/apsb14-13.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe Security Bulletin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/67092","name":"http://www.securityfocus.com/bid/67092","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Adobe Flash Player CVE-2014-0515 Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2014:0585-1: critical: update for flash-","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2014:0589-1: critical: update for flash-","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-0515","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0515","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"515","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"515","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:20:19.107Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"67092","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/67092"},{"name":"openSUSE-SU-2014:0585","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html"},{"name":"openSUSE-SU-2014:0589","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html"},{"name":"GLSA-201405-04","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-201405-04.xml"},{"name":"SUSE-SU-2014:0605","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html"},{"name":"RHSA-2014:0447","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0447.html"},{"name":"1030155","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030155"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://helpx.adobe.com/security/products/flash-player/apsb14-13.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-04-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-01-04T17:57:01.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"name":"67092","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/67092"},{"name":"openSUSE-SU-2014:0585","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html"},{"name":"openSUSE-SU-2014:0589","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html"},{"name":"GLSA-201405-04","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-201405-04.xml"},{"name":"SUSE-SU-2014:0605","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html"},{"name":"RHSA-2014:0447","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0447.html"},{"name":"1030155","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030155"},{"tags":["x_refsource_CONFIRM"],"url":"http://helpx.adobe.com/security/products/flash-player/apsb14-13.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2014-0515","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"67092","refsource":"BID","url":"http://www.securityfocus.com/bid/67092"},{"name":"openSUSE-SU-2014:0585","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html"},{"name":"openSUSE-SU-2014:0589","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html"},{"name":"GLSA-201405-04","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-201405-04.xml"},{"name":"SUSE-SU-2014:0605","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html"},{"name":"RHSA-2014:0447","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-0447.html"},{"name":"1030155","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030155"},{"name":"http://helpx.adobe.com/security/products/flash-player/apsb14-13.html","refsource":"CONFIRM","url":"http://helpx.adobe.com/security/products/flash-player/apsb14-13.html"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2014-0515","datePublished":"2014-04-29T10:00:00.000Z","dateReserved":"2013-12-20T00:00:00.000Z","dateUpdated":"2024-08-06T09:20:19.107Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-04-29 10:37:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0","versionEndExcluding":"11.2.202.346","matchCriteriaId":"0651AAFA-8F34-4A2B-AFEA-98327CBBD8F3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"155AD4FB-E527-4103-BCEF-801B653DEA37"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0","versionEndExcluding":"11.7.700.279","matchCriteriaId":"777C9188-DACA-47CC-B420-61FABAA5CBF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*","versionStartIncluding":"11.8","versionEndExcluding":"13.0.0.206","matchCriteriaId":"DEE08420-D3D6-4647-9EAE-B3986A231699"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","matchCriteriaId":"0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"515","Ordinal":"1","Title":"CVE-2014-0515","CVE":"CVE-2014-0515","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"515","Ordinal":"1","NoteData":"Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.","Type":"Description","Title":"CVE-2014-0515"},{"CveYear":"2014","CveId":"515","Ordinal":"2","NoteData":"2014-04-29","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"515","Ordinal":"3","NoteData":"2017-01-04","Type":"Other","Title":"Modified"}]}}}