CVE-2014-0540
Adobe Flash Player Vector Object Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, and CVE-2014-0545.
Adobe Flash Player anterior a 13.0.0.241 y 14.x anterior a 14.0.0.176 en Windows y OS X y anterior a 11.2.202.400 en Linux, Adobe AIR anterior a 14.0.0.178 en Windows y OS X y anterior a 14.0.0.179 en Android, Adobe AIR SDK anterior a 14.0.0.178, y Adobe AIR SDK & Compiler anterior a 14.0.0.178 no restringen debidamente el descubrimiento de las direcciones de memoria, lo que permite a atacantes evadir el mecanismo de protección ASLR a través de vectores no especificados, una vulnerabilidad diferente a CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, y CVE-2014-0545.
This vulnerability allows remote attackers to disclose memory addresses on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of Vector objects. By manipulating Vector objects an attacker can read arbitrary memory. An attacker can leverage this vulnerability to leak arbitrary memory addresses.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-20 CVE Reserved
- 2014-08-12 CVE Published
- 2024-06-24 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/60710 | Third Party Advisory | |
http://secunia.com/advisories/60732 | Third Party Advisory | |
http://www.securitytracker.com/id/1030712 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://helpx.adobe.com/security/products/flash-player/apsb14-18.html | 2017-01-07 |
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-201408-05.xml | 2017-01-07 | |
https://access.redhat.com/security/cve/CVE-2014-0540 | 2014-08-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1129417 | 2014-08-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 14.0.0.137 Search vendor "Adobe" for product "Adobe Air" and version " <= 14.0.0.137" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.83" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.111" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 14.0.0.110 Search vendor "Adobe" for product "Adobe Air" and version "14.0.0.110" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 13.0.0.231 Search vendor "Adobe" for product "Flash Player" and version " <= 13.0.0.231" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 13.0.0.231 Search vendor "Adobe" for product "Flash Player" and version " <= 13.0.0.231" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.182 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.182" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.182 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.182" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.201 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.201" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.201 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.201" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.206 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.206" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.206 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.206" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.214 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.214" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.214 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.214" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.223 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.223" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.223 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.223" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.125 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.125" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.125 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.125" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.145 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.145" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.145 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.145" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 14.0.0.110 Search vendor "Adobe" for product "Adobe Air" and version " <= 14.0.0.110" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 14.0.0.110 Search vendor "Adobe" for product "Adobe Air" and version " <= 14.0.0.110" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.83" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.83" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.111" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.111" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 11.2.202.394 Search vendor "Adobe" for product "Flash Player" and version " <= 11.2.202.394" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.223 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.223" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.228 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.228" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.233 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.233" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.235 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.235" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.236 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.236" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.238 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.238" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.243 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.243" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.251 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.251" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.258 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.258" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.261 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.261" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.262 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.262" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.270 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.270" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.273 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.273" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.275 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.275" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.280 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.280" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.285 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.285" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.291 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.291" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.297 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.297" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.310 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.310" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.332 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.332" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.335 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.335" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.336 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.336" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.341 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.341" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.346 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.346" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.350 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.350" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.356 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.356" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.359 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.359" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.378 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.378" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | <= 14.0.0.137 Search vendor "Adobe" for product "Adobe Air Sdk" and version " <= 14.0.0.137" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air Sdk" and version "13.0.0.83" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air Sdk" and version "13.0.0.111" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 14.0.0.110 Search vendor "Adobe" for product "Adobe Air Sdk" and version "14.0.0.110" | - |
Affected
|