CVE-2014-0531 Details
Description
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe adobe air | <= 13.0.0.111 13.0.0.83 |
CPE
Remediation
| |
| adobe flash player | <= 13.0.0.214 13.0.0.182 13.0.0.201 13.0.0.206 <= 11.2.202.359 11.2.202.223 11.2.202.228 11.2.202.233 11.2.202.235 11.2.202.236 11.2.202.238 11.2.202.243 11.2.202.251 11.2.202.258 11.2.202.261 11.2.202.262 11.2.202.270 11.2.202.273 11.2.202.275 11.2.202.280 11.2.202.285 11.2.202.291 11.2.202.297 11.2.202.310 11.2.202.332 11.2.202.335 11.2.202.336 11.2.202.341 11.2.202.346 11.2.202.350 11.2.202.356 |
CPE
Remediation
| |
| apple mac os x | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| adobe adobe air sdk | <= 13.0.0.111 13.0.0.83 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 22, 2017 | CVE Modified | [email protected] |
| Aug 5, 2014 | Initial Analysis | [email protected] |