Vulnerability Name:

CVE-2014-8439 (CCN-98932)

Assigned:2014-11-25
Published:2014-11-25
Updated:2021-09-22
Summary:Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-8439

Source: CONFIRM
Type: Vendor Advisory
http://helpx.adobe.com/security/products/flash-player/apsb14-22.html

Source: CCN
Type: Adobe Security Bulletin APSB14-26
Security updates available for Adobe Flash Player

Source: CONFIRM
Type: Vendor Advisory
http://helpx.adobe.com/security/products/flash-player/apsb14-26.html

Source: SUSE
Type: Third Party Advisory
openSUSE-SU-2014:1508

Source: SUSE
Type: Third Party Advisory
SUSE-SU-2014:1545

Source: SUSE
Type: Third Party Advisory
openSUSE-SU-2014:1562

Source: CCN
Type: RHSA-2014-1915
Critical: flash-plugin security update

Source: REDHAT
Type: Vendor Advisory
RHSA-2014:1915

Source: SECUNIA
Type: Permissions Required
60217

Source: BID
Type: Third Party Advisory, VDB Entry
71289

Source: CCN
Type: BID-71289
Adobe Flash Player CVE-2014-8439 Remote Code Execution Vulnerability

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1031259

Source: XF
Type: Third Party Advisory
adobe-flash-cve20148439-code-exec(98932)

Source: XF
Type: UNKNOWN
adobe-flash-cve20148439-code-exec(98932)

Source: CONFIRM
Type: Third Party Advisory
https://www.f-secure.com/weblog/archives/00002768.html

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-8439

Vulnerable Configuration:Configuration 1:
  • cpe:/a:adobe:flash_player:*:*:*:*:*:*:*:* (Version <= 11.2.202.418)
  • AND
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:adobe:air:*:*:*:*:*:*:*:* (Version <= 15.0.0.292)
  • OR cpe:/a:adobe:air_sdk_and_compiler:*:*:*:*:*:*:*:* (Version <= 15.0.0.301)
  • OR cpe:/a:adobe:air_sdk:*:*:*:*:*:*:*:* (Version <= 15.0.0.301)

  • Configuration 3:
  • cpe:/a:adobe:flash_player:*:*:*:*:*:*:*:* (Version <= 15.0.0.223)
  • AND
  • cpe:/o:apple:macos:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:adobe:flash_player:*:*:*:*:*:*:*:* (Version <= 13.0.0.252)
  • AND
  • cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras:5:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:adobe:flash_player:15.0.0.223:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux_server_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_8:-:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:52002
    P
    Security update for haproxy (Critical)
    2023-02-14
    oval:org.opensuse.security:def:5302
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:5335
    P
    Security update for postgresql10 (Important)
    2022-08-26
    oval:org.opensuse.security:def:5277
    P
    Security update for the Linux Kernel (Important)
    2022-06-20
    oval:org.opensuse.security:def:20148439
    V
    CVE-2014-8439
    2022-05-20
    oval:org.opensuse.security:def:6026
    P
    Security update for xen (Moderate)
    2022-05-03
    oval:org.opensuse.security:def:5366
    P
    Security update for flac (Moderate)
    2022-03-14
    oval:org.opensuse.security:def:5353
    P
    Security update for php72 (Moderate)
    2022-02-25
    oval:org.opensuse.security:def:5344
    P
    Security update for xen (Important)
    2022-02-17
    oval:org.opensuse.security:def:6004
    P
    Security update for MozillaFirefox (Important)
    2022-01-18
    oval:org.opensuse.security:def:10711
    P
    Security update for MozillaThunderbird (Important)
    2022-01-12
    oval:org.opensuse.security:def:5168
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:11148
    P
    Security update for hylafax+ (Moderate)
    2021-11-21
    oval:org.opensuse.security:def:11140
    P
    Security update for mbedtls (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:5121
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:10692
    P
    Security update for ffmpeg (Important)
    2021-09-02
    oval:org.opensuse.security:def:47162
    P
    syslog-service-2.0-778.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47005
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47233
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47067
    P
    libpulse-mainloop-glib0-32bit-5.0-2.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47871
    P
    python3-3.4.6-25.16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47131
    P
    ppc64-diag-2.7.1-5.6 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47925
    P
    xlockmore-5.43-5.30 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46921
    P
    cyrus-sasl-2.1.26-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:5075
    P
    Security update for the Linux Kernel (Important)
    2021-07-14
    oval:org.opensuse.security:def:11278
    P
    cron-4.2-55.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11534
    P
    flash-player-11.2.202.548-111.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11535
    P
    freerdp-1.0.2-7.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46469
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12099
    P
    ecryptfs-utils-103-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48718
    P
    flash-player-11.2.202.548-111.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11297
    P
    fetchmail-6.3.26-5.18 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17049
    P
    flash-player-11.2.202.548-111.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46560
    P
    python-2.7.7-2.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11439
    P
    perl-Tk-804.031-3.82 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12121
    P
    glib2-lang-2.48.2-10.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11372
    P
    libjson-c2-0.11-2.22 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46707
    P
    libXrender1-0.9.8-3.56 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11448
    P
    python-libxml2-2.9.1-6.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:76830
    P
    flash-player-11.2.202.548-111.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11263
    P
    accountsservice-0.6.35-1.126 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11397
    P
    libraw9-0.15.4-3.88 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11513
    P
    cups-pk-helper-0.2.5-3.75 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11461
    P
    strongswan-5.1.3-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:5053
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:10677
    P
    Security update for MozillaThunderbird (Moderate)
    2021-06-04
    oval:org.opensuse.security:def:51896
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:5045
    P
    Security update for postgresql10 (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:11216
    P
    Security update for exim (Critical)
    2021-05-20
    oval:org.opensuse.security:def:38103
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:5202
    P
    Security update for openssl-1_1 (Important)
    2021-03-25
    oval:org.opensuse.security:def:5183
    P
    Security update for ImageMagick (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:51723
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:11170
    P
    Security update for chromium (Important)
    2021-01-29
    oval:org.opensuse.security:def:51485
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:10584
    P
    Security update for MozillaThunderbird (Important)
    2020-12-07
    oval:org.opensuse.security:def:53912
    P
    Security update for transfig (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55381
    P
    sane-backends on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:46011
    P
    Security update for freeradius-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24597
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:24939
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:38214
    P
    gv on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52453
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52744
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:53427
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:37367
    P
    yast2-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37745
    P
    busybox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10853
    P
    systemtap-sdt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:46012
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:51322
    P
    Security update for jasper (Low)
    2020-12-01
    oval:org.opensuse.security:def:25084
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:10630
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:10786
    P
    librsvg-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52765
    P
    Security update for the Linux Kernel (Live Patch 15 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:53986
    P
    iputils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55455
    P
    Security update for flash-player (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24327
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24653
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38852
    P
    gnome-shell-calendar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51323
    P
    Security update for vim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52561
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:10554
    P
    libtiff-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52982
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:53712
    P
    Security update for u-boot (Important)
    2020-12-01
    oval:org.opensuse.security:def:37451
    P
    grub2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37835
    P
    krb5-appl-clients on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10862
    P
    xfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:46025
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25722
    P
    Security update for ovmf (Low)
    2020-12-01
    oval:org.opensuse.security:def:52581
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:10811
    P
    libxcb-composite0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52846
    P
    Security update for the Linux Kernel (Live Patch 11 for SLE 15 SP1) (Important)
    2020-12-01
    oval:org.opensuse.security:def:54024
    P
    libgadu3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24390
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:24736
    P
    Security update for sysstat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38142
    P
    bubblewrap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38894
    P
    flash-player on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51345
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:52582
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:53155
    P
    Security update for python-pip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53820
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:37587
    P
    libspice-server1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37995
    P
    libz1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10875
    P
    aaa_base-malloccheck on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:46145
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25026
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25757
    P
    Security update for flash-player (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10562
    P
    libwmf-0_2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52653
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:54122
    P
    squashfs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37355
    P
    xalan-j2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54105
    P
    procmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24516
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:24886
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:38170
    P
    dovecot22 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52168
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:52604
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:53261
    P
    Security update for 389-ds (Important)
    2020-12-01
    oval:org.opensuse.security:def:37356
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37688
    P
    sysvinit-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38054
    P
    rrdtool on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24317
    P
    Security update for openslp (Important)
    2020-12-01
    oval:org.opensuse.security:def:46337
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25040
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:52727
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:54196
    P
    flash-player on GA media (Moderate)
    2020-12-01
    oval:org.cisecurity:def:1252
    V
    Vulnerability in Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239, Adobe AIR before 15.0.0.293 - CVE-2014-8439
    2016-11-11
    oval:org.mitre.oval:def:28499
    P
    SUSE-SU-2014:1545-1 -- Security update for flash-player (important)
    2015-02-23
    oval:org.mitre.oval:def:28252
    P
    SUSE-SU-2014:1542-1 -- Security update for flash-player (moderate)
    2015-01-26
    oval:org.opensuse.security:def:78089
    P
    Security update for flash-player (Moderate)
    2014-11-28
    oval:com.redhat.rhsa:def:20141915
    P
    RHSA-2014:1915: flash-plugin security update (Critical)
    2014-11-26
    oval:com.ubuntu.precise:def:20148439000
    V
    CVE-2014-8439 on Ubuntu 12.04 LTS (precise) - medium.
    2014-11-25
    oval:com.ubuntu.trusty:def:20148439000
    V
    CVE-2014-8439 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-11-25
    BACK
    adobe flash player *
    linux linux kernel *
    adobe air *
    adobe air sdk and compiler *
    adobe air sdk *
    adobe flash player *
    apple macos *
    microsoft windows *
    adobe flash player *
    microsoft windows *
    apple mac os x *
    adobe flash player 15.0.0.223
    redhat enterprise linux server supplementary 6
    redhat enterprise linux workstation supplementary 6
    redhat enterprise linux desktop supplementary 6
    redhat enterprise linux hpc node supplementary 6
    microsoft windows 8 -
    microsoft windows 8.1 - -