CVE-2014-0541 – flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
https://notcve.org/view.php?id=CVE-2014-0541
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 allow attackers to bypass intended access restrictions via unspecified vectors. Adobe Flash Player anterior a 13.0.0.241 y 14.x anterior a 14.0.0.176 en Windows y OS X y anterior a 11.2.202.400 en Linux, Adobe AIR anterior a 14.0.0.178 en Windows y OS X y anterior a 14.0.0.179 en Android, Adobe AIR SDK anterior a 14.0.0.178, y Adobe AIR SDK & Compiler anterior a 14.0.0.178 permiten a atacantes evadir las restricciones de acceso a través de vectores no especificados. • http://helpx.adobe.com/security/products/flash-player/apsb14-18.html http://secunia.com/advisories/58593 http://secunia.com/advisories/59904 http://secunia.com/advisories/60710 http://secunia.com/advisories/60732 http://security.gentoo.org/glsa/glsa-201408-05.xml http://www.securitytracker.com/id/1030712 https://access.redhat.com/security/cve/CVE-2014-0541 https://bugzilla.redhat.com/show_bug.cgi?id=1129417 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-0538 – flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
https://notcve.org/view.php?id=CVE-2014-0538
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 allows attackers to execute arbitrary code via unspecified vectors. Vulnerabilidad de uso después de liberación en Adobe Flash Player anterior a 13.0.0.241 y 14.x anterior a 14.0.0.176 en Windows y OS X y anterior a 11.2.202.400 en Linux, Adobe AIR anterior a 14.0.0.178 en Windows y OS X y anterior a 14.0.0.179 en Android, Adobe AIR SDK anterior a 14.0.0.178, y Adobe AIR SDK & Compiler anterior a 14.0.0.178 permite a atacantes ejecutar código arbitrario a través de vectores no especificados. • http://helpx.adobe.com/security/products/flash-player/apsb14-18.html http://secunia.com/advisories/58593 http://secunia.com/advisories/59904 http://secunia.com/advisories/60710 http://secunia.com/advisories/60732 http://security.gentoo.org/glsa/glsa-201408-05.xml http://security.gentoo.org/glsa/glsa-201408-16.xml http://www.securitytracker.com/id/1030712 https://access.redhat.com/security/cve/CVE-2014-0538 https://bugzilla.redhat.com/show_bug.cgi?id=1129417 •
CVE-2014-0543 – flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
https://notcve.org/view.php?id=CVE-2014-0543
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0540, CVE-2014-0542, CVE-2014-0544, and CVE-2014-0545. Adobe Flash Player anterior a 13.0.0.241 y 14.x anterior a 14.0.0.176 en Windows y OS X y anterior a 11.2.202.400 en Linux, Adobe AIR anterior a 14.0.0.178 en Windows y OS X y anterior a 14.0.0.179 en Android, Adobe AIR SDK anterior a 14.0.0.178, y Adobe AIR SDK & Compiler anterior a 14.0.0.178 no restringen debidamente el descubrimiento de direcciones de memoria, lo que permite a atacantes evadir el mecanismo de protección ASLR a través de vectores no especificados, una vulnerabilidad diferente a CVE-2014-0540, CVE-2014-0542, CVE-2014-0544, y CVE-2014-0545. • http://helpx.adobe.com/security/products/flash-player/apsb14-18.html http://secunia.com/advisories/60710 http://secunia.com/advisories/60732 http://security.gentoo.org/glsa/glsa-201408-05.xml http://www.securitytracker.com/id/1030712 https://access.redhat.com/security/cve/CVE-2014-0543 https://bugzilla.redhat.com/show_bug.cgi?id=1129417 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-0545 – flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
https://notcve.org/view.php?id=CVE-2014-0545
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, and CVE-2014-0544. Adobe Flash Player anterior a 13.0.0.241 y 14.x anterior a 14.0.0.176 en Windows y OS X y anterior a 11.2.202.400 en Linux, Adobe AIR anterior a 14.0.0.178 en Windows y OS X y anterior a 14.0.0.179 en Android, Adobe AIR SDK anterior a 14.0.0.178, y Adobe AIR SDK & Compiler anterior a 14.0.0.178 no restringen debidamente el descubrimiento de las direcciones de la memoria, lo que permite a atacantes evadir el mecanismo de protección ASLR a través de vectores no especificados, una vulnerabilidad diferente a CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, y CVE-2014-0544. • http://helpx.adobe.com/security/products/flash-player/apsb14-18.html http://secunia.com/advisories/60710 http://secunia.com/advisories/60732 http://security.gentoo.org/glsa/glsa-201408-05.xml http://www.securitytracker.com/id/1030712 https://access.redhat.com/security/cve/CVE-2014-0545 https://bugzilla.redhat.com/show_bug.cgi?id=1129417 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-0540 – Adobe Flash Player Vector Object Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2014-0540
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, and CVE-2014-0545. Adobe Flash Player anterior a 13.0.0.241 y 14.x anterior a 14.0.0.176 en Windows y OS X y anterior a 11.2.202.400 en Linux, Adobe AIR anterior a 14.0.0.178 en Windows y OS X y anterior a 14.0.0.179 en Android, Adobe AIR SDK anterior a 14.0.0.178, y Adobe AIR SDK & Compiler anterior a 14.0.0.178 no restringen debidamente el descubrimiento de las direcciones de memoria, lo que permite a atacantes evadir el mecanismo de protección ASLR a través de vectores no especificados, una vulnerabilidad diferente a CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, y CVE-2014-0545. This vulnerability allows remote attackers to disclose memory addresses on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Vector objects. By manipulating Vector objects an attacker can read arbitrary memory. • http://helpx.adobe.com/security/products/flash-player/apsb14-18.html http://secunia.com/advisories/60710 http://secunia.com/advisories/60732 http://security.gentoo.org/glsa/glsa-201408-05.xml http://www.securitytracker.com/id/1030712 https://access.redhat.com/security/cve/CVE-2014-0540 https://bugzilla.redhat.com/show_bug.cgi?id=1129417 • CWE-264: Permissions, Privileges, and Access Controls •