Vulnerability Name: | CVE-2014-0510 (CCN-92683) | ||||||||||||||||||||||||||||||||
Assigned: | 2013-12-20 | ||||||||||||||||||||||||||||||||
Published: | 2014-03-13 | ||||||||||||||||||||||||||||||||
Updated: | 2014-06-21 | ||||||||||||||||||||||||||||||||
Summary: | Heap-based buffer overflow in Adobe Flash Player 12.0.0.77 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Zeguang Zhao and Liang Chen during a Pwn2Own competition at CanSecWest 2014. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-0510 Source: CCN Type: Adobe Web site Flash Player Source: CCN Type: Adobe Product Security Bulletin APSB14-14 Security updates available for Adobe Flash Player Source: CONFIRM Type: UNKNOWN http://helpx.adobe.com/security/products/flash-player/apsb14-14.html Source: SUSE Type: UNKNOWN SUSE-SU-2014:0671 Source: CCN Type: RHSA-2014-0496 Critical: flash-plugin security update Source: REDHAT Type: UNKNOWN RHSA-2014:0496 Source: GENTOO Type: UNKNOWN GLSA-201406-08 Source: MISC Type: UNKNOWN http://twitter.com/thezdi/statuses/444262022444621824 Source: CCN Type: Pwn2Own Web site Pwn2Own results for Thursday (Day Two) Source: MISC Type: UNKNOWN http://www.pwn2own.com/2014/03/pwn2own-results-thursday-day-two/ Source: BID Type: UNKNOWN 66241 Source: CCN Type: BID-66241 Adobe Flash Player and Adobe AIR CVE-2014-0510 Heap Based Buffer Overflow Vulnerability Source: XF Type: UNKNOWN adobe-flash-cve20140510-bo(92683) Source: CCN Type: ZDI-14-130 (Pwn2Own) Adobe Flash Display Object Memory Corruption Remote Code Execution Vulnerability | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |