CVE-2014-5333
flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.
Adobe Flash Player en versiones anteriores a 13.0.0.241 y 14.x en versiones anteriores a 14.0.0.176 en Windows y OS X y en versiones anteriores a 11.2.202.400 en Linux, Adobe AIR en versiones anteriores a 14.0.0.178 en Windows y OS X y en versiones anteriores a 14.0.0.179 en Android, Adobe AIR SDK en versiones anteriores a 14.0.0.178 y Adobe AIR SDK & Compiler en versiones anteriores a 14.0.0.178 no restringe adecuadamente el formato de archivo SWF, lo que permite a atacantes remotos llevar a cabo ataques de CSRF contra puntos finales JSONP y obtener información sensible, a través de un elemento OBJECT manipulado con contenido SWF que satisface los requerimientos de set de caractéres de una llamada de retorno API, en conjunto con una manipulación que involucra un caracter '$' (signo de dolar) o '(' (paréntesis abierto). NOTA: este problema existe por un arreglo incompleto para CVE-2014-4671.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-08-18 CVE Reserved
- 2014-08-19 CVE Published
- 2024-05-15 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://miki.it/blog/2014/8/15/adobe-really-fixed-rosetta-flash-today | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95418 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://helpx.adobe.com/security/products/flash-player/apsb14-18.html | 2017-09-08 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2014-5333 | 2014-08-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1129417 | 2014-08-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 14.0.0.137 Search vendor "Adobe" for product "Adobe Air" and version " <= 14.0.0.137" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.83" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.111" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 14.0.0.110 Search vendor "Adobe" for product "Adobe Air" and version "14.0.0.110" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 13.0.0.231 Search vendor "Adobe" for product "Flash Player" and version " <= 13.0.0.231" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 13.0.0.231 Search vendor "Adobe" for product "Flash Player" and version " <= 13.0.0.231" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.182 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.182" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.182 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.182" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.201 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.201" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.201 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.201" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.206 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.206" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.206 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.206" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.214 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.214" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.214 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.214" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.223 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.223" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.223 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.223" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.125 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.125" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.125 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.125" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.145 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.145" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.145 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.145" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 11.2.202.394 Search vendor "Adobe" for product "Flash Player" and version " <= 11.2.202.394" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.223 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.223" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.228 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.228" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.233 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.233" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.235 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.235" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.236 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.236" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.238 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.238" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.243 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.243" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.251 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.251" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.258 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.258" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.261 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.261" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.262 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.262" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.270 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.270" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.273 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.273" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.275 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.275" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.280 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.280" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.285 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.285" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.291 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.291" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.297 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.297" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.310 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.310" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.332 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.332" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.335 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.335" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.336 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.336" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.341 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.341" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.346 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.346" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.350 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.350" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.356 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.356" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.359 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.359" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.378 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.378" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 14.0.0.110 Search vendor "Adobe" for product "Adobe Air" and version " <= 14.0.0.110" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 14.0.0.110 Search vendor "Adobe" for product "Adobe Air" and version " <= 14.0.0.110" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.83" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.83" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.111" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.111" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | <= 14.0.0.137 Search vendor "Adobe" for product "Adobe Air Sdk" and version " <= 14.0.0.137" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air Sdk" and version "13.0.0.83" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air Sdk" and version "13.0.0.111" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 14.0.0.110 Search vendor "Adobe" for product "Adobe Air Sdk" and version "14.0.0.110" | - |
Affected
|