CVE-2014-0515

critical
Published 2014-04-29 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — http://helpx.adobe.com/security/products/flash-player/apsb14-13.html

OS impact

OSVersionStatusFixed in
macos macosnot-affected
linux linux-kernelnot-affected

Application impact

VendorProductVersionsFixed
adobeflash_player{"startIncluding":"11.0","endExcluding":"11.2.202.346"}11.2.202.346

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.