CVE-2014-0502 Details
Description
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 20, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Adobe Flash Player Double Free Vulnerablity | Sep 17, 2024 | Oct 8, 2024 | The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-415 | Double Free | [email protected] |
| CWE-415 | Double Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| adobe flash player | < 11.7.700.269 >= 11.8.800.94, < 12.0.0.70 < 11.2.202.341 |
CPE
Remediation
| |
| apple mac os x | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| adobe adobe air sdk | < 4.0.0.1628 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| adobe adobe air | < 4.0.0.1628 |
CPE
Remediation
| |
| google android | All versions |
CPE
Remediation
| |
| opensuse opensuse | 11.4 12.3 13.1 |
CPE
Remediation
| |
| suse linux enterprise desktop | 11 sp3 |
CPE
Remediation
| |
| redhat enterprise linux desktop | 5.0 6.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 6.5 |
CPE
Remediation
| |
| redhat enterprise linux server | 5.0 6.0 |
CPE
Remediation
| |
| redhat enterprise linux server aus | 6.5 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 5.0 6.0 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 21, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Dec 20, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 19, 2024 | Modified Analysis | [email protected] |
| Sep 18, 2024 | CVE Modified | CISA-ADP |
| Sep 18, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 13, 2018 | Modified Analysis | [email protected] |
| Jan 20, 2017 | CVE Modified | [email protected] |
| Feb 21, 2014 | Initial Analysis | [email protected] |