Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability

BID:66122

Info

Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability

Bugtraq ID: 66122
Class: Origin Validation Error
CVE: CVE-2014-0503
Remote: Yes
Local: No
Published: Mar 11 2014 12:00AM
Updated: Mar 19 2015 08:30AM
Credit: Masato Kinugawa
Vulnerable: SuSE Suse Linux Enterprise Desktop 11 SP3
S.u.S.E. openSUSE 12.3
S.u.S.E. openSUSE 11.4
Redhat Enterprise Linux Workstation Supplementary 6
Redhat Enterprise Linux Supplementary 5 server
Redhat Enterprise Linux Server Supplementary 6
Redhat Enterprise Linux Desktop Supplementary 6
Redhat Enterprise Linux Desktop Supplementary 5 client
Google Chrome 33.0.1750.92
Google Chrome 33.0.1750.90
Google Chrome 33.0.1750.89
Google Chrome 33.0.1750.85
Google Chrome 33.0.1750.82
Google Chrome 33.0.1750.80
Google Chrome 33.0.1750.79
Google Chrome 33.0.1750.76
Google Chrome 33.0.1750.74
Google Chrome 33.0.1750.71
Google Chrome 33.0.1750.7
Google Chrome 33.0.1750.68
Google Chrome 33.0.1750.66
Google Chrome 33.0.1750.64
Google Chrome 33.0.1750.62
Google Chrome 33.0.1750.60
Google Chrome 33.0.1750.59
Google Chrome 33.0.1750.57
Google Chrome 33.0.1750.55
Google Chrome 33.0.1750.53
Google Chrome 33.0.1750.51
Google Chrome 33.0.1750.5
Google Chrome 33.0.1750.48
Google Chrome 33.0.1750.46
Google Chrome 33.0.1750.44
Google Chrome 33.0.1750.42
Google Chrome 33.0.1750.40
Google Chrome 33.0.1750.39
Google Chrome 33.0.1750.37
Google Chrome 33.0.1750.35
Google Chrome 33.0.1750.31
Google Chrome 33.0.1750.3
Google Chrome 33.0.1750.28
Google Chrome 33.0.1750.26
Google Chrome 33.0.1750.24
Google Chrome 33.0.1750.22
Google Chrome 33.0.1750.20
Google Chrome 33.0.1750.19
Google Chrome 33.0.1750.16
Google Chrome 33.0.1750.146
Google Chrome 33.0.1750.144
Google Chrome 33.0.1750.14
Google Chrome 33.0.1750.135
Google Chrome 33.0.1750.132
Google Chrome 33.0.1750.13
Google Chrome 33.0.1750.125
Google Chrome 33.0.1750.124
Google Chrome 33.0.1750.117
Google Chrome 33.0.1750.116
Google Chrome 33.0.1750.113
Google Chrome 33.0.1750.111
Google Chrome 33.0.1750.11
Google Chrome 33.0.1750.108
Google Chrome 33.0.1750.106
Google Chrome 33.0.1750.10
Google Chrome 33.0.1750.0
Gentoo Linux
Adobe Flash Player for Windows 8.1 12.0.0.38
Adobe Flash Player for Windows 8.0 12.0.0.38
Adobe Flash Player for Windows 12.0 70
Adobe Flash Player for Windows 11.7.700 169
Adobe Flash Player for Windows 12.0.0.44
Adobe Flash Player for Windows 12.0.0.43
Adobe Flash Player for Windows 12.0.0.41
Adobe Flash Player for Windows 11.9.900.170
Adobe Flash Player for Windows 11.7.700.269
Adobe Flash Player for Windows 11.6.602.180
Adobe Flash Player for Macintosh 12.0 70
Adobe Flash Player for Macintosh 12.0.0.44
Adobe Flash Player for Macintosh 12.0.0.41
Adobe Flash Player for Macintosh 12.0.0.38
Adobe Flash Player for Macintosh 11.9.900.170
Adobe Flash Player for Macintosh 11.7.700.269
Adobe Flash Player for Chrome 12.0 70
Adobe Flash Player for Chrome 11.7.700 202
Adobe Flash Player for Chrome 11.7.700 169
Adobe Flash Player for Chrome 12.0.0.44
Adobe Flash Player for Chrome 12.0.0.41
Adobe Flash Player for Chrome 11.6.602.180
Adobe Flash Player for Chrome 11.6.602.171
Adobe Flash Player for Chrome 11.5.31.5
Adobe Flash Player for Chrome 11.5.31.137
Adobe Flash Player for Chrome 11.4.402.287
Adobe Flash Player for Chrome 11.4.402.265
Adobe Flash Player for Chrome 11.3.31.331
Adobe Flash Player for Chrome 11.3.31.230
Adobe Flash Player for Chrome 11.3.31.110
Adobe Flash Player for Chrome 11.3.300.271
Not Vulnerable: Google Chrome 33.0.1750.149
Adobe Flash Player for Windows 12.0 77
Adobe Flash Player for Windows 11.7.700 272
Adobe Flash Player for Macintosh 12.0 77
Adobe Flash Player for Macintosh 11.7.700 272
Adobe Flash Player for Chrome 12.0 77

Discussion

Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability

Adobe Flash Player is prone to an unspecified security-bypass vulnerability.

An attacker can exploit this issue to bypass certain same-origin policy restrictions, which may aid in further attacks.

Exploit / POC

Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability

Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability

Solution:
Updates are available. Please see the references or vendor advisory for more information.

References

Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report